Skip to content

Escape HTML characters in comboxbox options#8

Open
kycook wants to merge 2 commits intodellsala:masterfrom
kycook:patch1
Open

Escape HTML characters in comboxbox options#8
kycook wants to merge 2 commits intodellsala:masterfrom
kycook:patch1

Conversation

@kycook
Copy link

@kycook kycook commented Sep 17, 2012

If you had combobox options that contained HTML characters, such as test, it would render the option as text instead of test. This is especially dangerous if the combo-box is showing user-inputted values because it could lead to script injection.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant