Details
-
Bug
-
Resolution: Fixed
-
Blocker
-
4.2-milestone-2
-
Unit
-
Unknown
-
N/A
-
N/A
-
Description
Steps to reproduce:
Write $escapetool.html('{') in Velocity code.
Expected result:
The { is escaped.
Actual result:
The character { is printed as-is. This is unexpected as since XWIKI-7894, $escapetool.xml escapes {. This causes security vulnerabilities like XWIKI-21438 - I'm thus classifying it the same.
Attachments
Issue Links
- relates to
-
XWIKI-21438 Remote code execution from view right on Panels.PanelLayoutUpdate
- Closed
- links to