Trigger a workflow via JavaScript

Standard considerations about security apply, the most critical is: are you inserting user generated content in the html component?
If yes you should assess if this can be a problem in your specific case.

Here is an example:
chrome_4EKBR3O0FK

A custom plugin instead can avoid this kind of problem.

2 Likes