XSS on search box 4.3

This topic was automatically closed 365 days after the last reply. New replies are no longer allowed.
Hace 2 años
I'm getting some XSS issues in the search page on Nop 4.3
If I add </script>"><script>prompt(1)</script> on search box and hit enter, it shows the prompt on the screen before load the search results page.
Do we have any fix for this?
Hace 2 años
It works absolutely fine out of the box (no XSS).

Are you using any third-party plugins?
Hace 2 años
I'm not using any third party package.
I will compare the objects on git with my code and get back to you.
Thanks for now.
This topic was automatically closed 365 days after the last reply. New replies are no longer allowed.