-
Bug
-
Resolution: Duplicate
-
Critical
-
6.4.0
When you create a new task filtered list in business central, you can use HTML tags for the Name field. Later, when deleting it, the HTML is rendered. Although tags like script seems to be rejected, this could be an entry point for XSS attacks.
- is cloned by
-
RHBPMS-4625 CVE-2017-2674 business-central: Multiple stored XSS in task and process filters [bpms-6.4.x]
- Closed