legacy-knowledge-base
公開されました Jun. 30, 2025

XSS Vulnerability present when using Web Content Article's source code

投稿者

Adrienne Lao

knowledge-article-header-disclaimer-how-to

knowledge-article-header-disclaimer

legacy-article

learn-legacy-article-disclaimer-text

Issue

  • We've observed a XSS Vulnerability present when using Web Content Article's source code. 
  • This vulnerability appears to be present when involving the deployment of a payload via the source code. 
  • Steps to reproduce:
    1. Create a Web Content Article
    2. Edit the <> Source Code and add the payload:
      synack<img src=x onerror=alert(location)>
    3. Publish
    4. Attempt to edit/preview the article and observe that a pop-up window appears containing what appears to be a patch to the article. 

Environment

  • DXP 7.3

Resolution

  • This behavior has been addressed in LPE-17988. Please request a hotfix including this LPE to resolve the behavior.

 

 

did-this-article-resolve-your-issue

legacy-knowledge-base