Style tag onload events in XSSAPI | Adobe Higher Education
Skip to main content
Kishore_Kumar_
Level 9
February 5, 2020

Style tag onload events in XSSAPI

  • February 5, 2020
  • 0 svar
  • 1621 visningar

Both cq(com.adobe.granite.xss.xssapi) and sling(org.apache.sling.xss.XSSAPI) xss filterHTML() methods allows the events in style tag which causes security threat. May i know how to restrict it ?

Eg.

xssAPI.filterHTML("<style onload=\"alert()\">test</style>") - Instead of removing the onload events, it's allowing the alert.

Det här ämnet har stängts för svar.