Issue #3300530: XSS filter is bypassed in current implementation

Merge request reports

Loading