| Issue: |
|
|---|---|
| Date: |
|
| Severity: | Low |
| Requires Admin Access: | No |
| Fix Version: | n/a |
| Credit: | Internal Security Team |
| Description: |
The web application was found to include JavaScript hosted on third party servers within the application: |
| Mitigation: |
dotCMS requires this script in order to provide backward compatibility for older IE browsers. In this case, we treat ajax.googleapis.com as a "trusted" domain. |