SAP Note 1275278 - Security: HTML Encoding missing over the inputField tooltip

Component : Tag Library - Tag Library

Solution : https://service.sap.com/sap/support/notes/1275278 (SAP Service marketplace login required)

Key words :
cross-site scripting, missing html encoding, malicious code reason, user enters, javascript code, http filter, dangerous content, inputfield tooltip, javascript, conditions

Related Notes :

1530970Double-encoding of tooltips
888889Automatic checks for security notes using RSECNOTE