Ticket #5616 (new defect)
Opened 2 years ago
Last modified 1 year ago
[PATCH] sanitize(html) should prohibit href and style attributes with "javascript:" even if "javascript:" contains newlines
| Reported by: | kamens@gmail.com | Assigned to: | David |
|---|---|---|---|
| Priority: | normal | Milestone: | |
| Component: | ActionPack | Version: | |
| Severity: | normal | Keywords: | sanitize html javascript |
| Cc: |