apinf / platform

Apinf - Open source API management platform with multi proxy and protocol support
https://apinf.com/
European Union Public License 1.1
74 stars 35 forks source link

Security: script can be injected via custom html editor #3609

Open Nazarah opened 5 years ago

Nazarah commented 5 years ago

Reproduction Step:

  1. Login as Admin
  2. Under User > Branding, add the following text in Custom HTML block: 1"/>;
  3. click Save
  4. Navigate to Pricing menu

Actual Result: On arrival, a popup appears where user can paste strings/scripts.