The current ThingWorx 8.5 solution uses non-encoded asterisk (*) in URLs as a part of the composer user interface. The use of non-encoded asterisk (*) in URLs is a security issue that introduces the possibility of CSS attacks. This is an issue for customers that deploy ThingWorx in highly secured environments.
This enhancement request is to have the ThingWorx product updated to either remove the use of asterisk (*) in URLs or to properly encode them.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.