project_key: JBEPP in site, click on edit navigation for classic portal in page selector tab, type "anything" in the name and "Site Map<script>alert('a');</script>" into title click create page and dialog disappears
Technical note added. If any revisions are required, please edit the "Technical Notes" field accordingly. All revisions will be proofread by the Engineering Content Services team. New Contents: CAUSE: Entered text becomes part of portal page HTML as-is, including special characters like angle brackets CONSEQUENCE: Entered text can break a portal page FIX: Prevent entry of angle brackets using NoHTMLTagValidator RESULT: Text that could break a portal page can't be entered any more. If angle brackets are desired in the output, character references can be used - &lt; and &gt;
Technical note updated. If any revisions are required, please edit the "Technical Notes" field accordingly. All revisions will be proofread by the Engineering Content Services team. Diffed Contents: @@ -1,4 +1,4 @@ CAUSE: Entered text becomes part of portal page HTML as-is, including special characters like angle brackets CONSEQUENCE: Entered text can break a portal page FIX: Prevent entry of angle brackets using NoHTMLTagValidator -RESULT: Text that could break a portal page can't be entered any more. If angle brackets are desired in the output, character references can be used - &lt; and &gt;+RESULT: Text that could break a portal page can't be entered any more. If angle brackets are desired in the output, character references can be used - < and >
Deleted Technical Notes Contents. Old Contents: CAUSE: Entered text becomes part of portal page HTML as-is, including special characters like angle brackets CONSEQUENCE: Entered text can break a portal page FIX: Prevent entry of angle brackets using NoHTMLTagValidator RESULT: Text that could break a portal page can't be entered any more. If angle brackets are desired in the output, character references can be used - < and >