Skip to content

Commit 9470f5e

Browse files
authored
Update docs/infrastructure_and_maintenance/security/security_checklist.md
1 parent 5abd874 commit 9470f5e

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

docs/infrastructure_and_maintenance/security/security_checklist.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -146,7 +146,8 @@ Reduce your attack surface by exposing only what you must.
146146

147147
### Limit access to code blocks
148148

149-
The Code Block in Page Builder is designed to accept any HTML, which includes embedded JavaScript. This means that XSS is necessarily possible for editors that have access to Code Blocks. As site administrator you should be aware of this when giving editors access to the Page Builder features, and limit that access only to highly trusted editors. It is possible to
149+
The [Code block]([[= user_doc =]]/content_management/block_reference/#code-block) in Page Builder is designed to accept any HTML, which includes embedded JavaScript.
150+
This means that malicious JS including cross site scripting (XSS) is necessarily possible for editors that have access to Code blocks. As site administrator you should be aware of this when giving editors access to the Page Builder features, and limit that access only to highly trusted editors. It is possible to
150151
[limit access to specific blocks per content type]([[= user_doc =]]/content_management/configure_ct_field_settings/#default-configuration-of-pages),
151152
where you can define which page blocks are available to an editor.
152153

0 commit comments

Comments
 (0)