-
Type:
Task
-
Resolution: Fixed
-
Priority:
L3 - Default
-
Affects Version/s: None
-
Component/s: webapp
-
None
Problem
With the newly introduced translate directive it is possible to inject arbitrary HTML and JavaScript via HTML script tag.
Solution
Enable angular-translate sanitization strategy: http://angular-translate.github.io/docs/#/guide/19_security
This is the controller panel for Smart Panels app
- is related to
-
CAM-9549 Update main frontend framework libraries to latest maintained versions
-
- Closed
-