You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The most common subject of invalid reports that the security team receives is editors and administrators being able to include JavaScript in post content.
Section A3 - Cross Site Scripting (XSS) mentions this, but only briefly. I think this ought to be moved into its own heading. After all, it's an important security point for people to be aware of.
The text was updated successfully, but these errors were encountered:
johnbillion
changed the title
Improve section A3 - Cross Site Scripting (XSS)
Improve section about JavaScript in post content
Mar 7, 2017
The most common subject of invalid reports that the security team receives is editors and administrators being able to include JavaScript in post content.
Section
A3 - Cross Site Scripting (XSS)
mentions this, but only briefly. I think this ought to be moved into its own heading. After all, it's an important security point for people to be aware of.The text was updated successfully, but these errors were encountered: