-
Bug
-
Resolution: Fixed
-
Critical
-
1.2.3, 1.3
-
None
-
-
Empty show more show less
Currently it is possible to overlay page content via search field in default branding template.
Workaround:
- in AdminCentral go to Templating Kit/Templates.
- in the template tree open the branding template at /templating-kit/templates/global/branding
- replace <input id="searchbar" name="queryStr" type="text" value="${ctx.queryStr!}" /> with <input id="searchbar" name="queryStr" type="text" value="${ctx.queryStr!?html}" />
- make sure "Enable template" checkbox is checked
- click Save
Acceptance criteria
- is duplicated by
-
MGNLSTK-660 XSS leak in standard search field
- Closed
- mentioned in
-
Wiki Page Loading...