Openbravo Issue Tracking System - Openbravo ERP
View Issue Details
0056995Openbravo ERPA. Platformpublic2024-10-14 08:112024-11-28 12:58
alostale 
Triage Platform Base 
normalmajorhave not tried
scheduledopen 
5
 
PR24Q3.3 
Core
No
0056995: broken layout in window title
When opening a link to Openbravo backoffice if the title of a view contains some special characters the layout can be broken.
Try to open some link like:

https://localhost:8080/openbravo/#%7Bst:0,bm:%5B%7BviewId:__X__,params:%7BtabTitle:__%3Cimg%20src=a%20onerr [^]
or=alert()%3E__%7D%7D%5D%7D
Properly treat/escape tab titles when rendering them.
No tags attached.
blocks defect 0056754 closed Triage Platform Base broken layout in window title 
Issue History
2024-11-05 18:53AugustoMauchTypedefect => backport
2024-11-05 18:53AugustoMauchTarget Version => PR24Q3.3
2024-11-28 12:58hgbotNote Added: 0172712

Notes
(0172712)
hgbot   
2024-11-28 12:58   
Merge Request created: https://gitlab.com/openbravo/product/openbravo/-/merge_requests/1461 [^]