Register now to learn Fabric in free live sessions led by the best Microsoft experts. From Apr 16 to May 9, in English and Spanish.
Hi,
We have BI Reports with comment feature where user can post any comments, in the security check we noticed that there is no validation on user comments to prevent data validation attack such as cross-site scripting or link Injection. Is there any or centralized validation module to prevent such contents post.
Regards,
Ravi
Hello - I am concerned about same - how does MS prevent cross site scripting threats in the PBI web browser ?
Is the browser code ( javascript/html ) is output encoded so that any bad data masking as code that may possibly be retrieved from a data source would not be able to impact the PBI gateway browser ?
Hi Ravi,
I don't see the issue here. How can you create an XSS in the comments?
Covering the world! 9:00-10:30 AM Sydney, 4:00-5:30 PM CET (Paris/Berlin), 7:00-8:30 PM Mexico City
Check out the April 2024 Power BI update to learn about new features.
User | Count |
---|---|
12 | |
2 | |
2 | |
1 | |
1 |