Skip to content
This repository has been archived by the owner on Aug 21, 2019. It is now read-only.

Plugin is vulnerable to xss #12

Open
AKoetsier opened this issue Sep 19, 2011 · 1 comment
Open

Plugin is vulnerable to xss #12

AKoetsier opened this issue Sep 19, 2011 · 1 comment
Labels

Comments

@AKoetsier
Copy link

The value from the object is marked as html_safe. I think it should be escaped by default and make the plugin output raw values when this is selected in the options.

@soyuka
Copy link

soyuka commented Feb 26, 2012

+1
Even with callback or data or loadUrl, I still get a flash from html and <script> are working...

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

No branches or pull requests

2 participants