Skip to content

short: prevent XSS-injection#104

Open
Krassmus wants to merge 1 commit intomichael:masterfrom
Krassmus:patch-1
Open

short: prevent XSS-injection#104
Krassmus wants to merge 1 commit intomichael:masterfrom
Krassmus:patch-1

Conversation

@Krassmus
Copy link

longer: if the option is "yeah<script>alert('test')</script>" it would be transformed with multiselect so that a javascript alert is started. This change prevents this behaviour.

longer: if the option is "<option>yeah&lt;script&gt;alert('test')&lt;/script&gt;</option>" it would be transformed with multiselect so that a javascript alert is started. This change prevents this behaviour.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant