The XSS here is only possible if CSP is disabled. Low impact since CSP is enabled by default in SiteSettings. |
||
|---|---|---|
| .. | ||
| assets | ||
| controllers | ||
| helpers | ||
| jobs | ||
| mailers | ||
| models | ||
| serializers | ||
| services | ||
| views | ||
The XSS here is only possible if CSP is disabled. Low impact since CSP is enabled by default in SiteSettings. |
||
|---|---|---|
| .. | ||
| assets | ||
| controllers | ||
| helpers | ||
| jobs | ||
| mailers | ||
| models | ||
| serializers | ||
| services | ||
| views | ||