https://issues.apache.org/jira/browse/OFBIZ-12249?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17359434#comment-17359434 ]
Xin Wang commented on OFBIZ-12249:
Hi Jacques,
To make my opinion more clear, I have filed another issue OFBIZ-12254, which is related to a XSS vulnerability.
Although this vulnerability is only valid when `sanitizer.enable` is disabled. but the point is that we can escaping text properly to prevent that problem, without the help of sanitizer, as shown in the attached patch.
This message was sent by Atlassian Jira