[ 
https://issues.apache.org/jira/browse/ISIS-3251?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jörg Rade resolved ISIS-3251.
-----------------------------
    Resolution: Cannot Reproduce

Screen now shows the malicious string in an escaped from.

> [WicketViewer] Escape String in Table
> -------------------------------------
>
>                 Key: ISIS-3251
>                 URL: https://issues.apache.org/jira/browse/ISIS-3251
>             Project: Isis
>          Issue Type: Bug
>          Components: Isis Viewer Wicket
>    Affects Versions: 2.0.0-M9
>            Reporter: Jörg Rade
>            Assignee: Andi Huber
>            Priority: Major
>             Fix For: 2.0.0-RC1
>
>         Attachments: 2022-10-15 11_41_12-6 Products.png, 2022-10-15 
> 11_42_09-DbVisualizer Free 10.0.16 - knife_postgres_knife_TABLE_product.png, 
> 2022-10-17 11_20_21-DevTools - 
> localhost_8080_wicket_entity_knife.HomePageViewModel_AKztAAVzcgARamF2.png
>
>
> Strings from DB (inserted via SQL, not via UI) are not escaped when rendered 
> in a table.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to