Backport #5570 - Immediate fix to htmlEncode user added text #5575

Merged
lunny merged 2 commits from backport-5570 into release/v1.6 2018-12-21 14:05:48 +00:00
Contributor

There are likely problems remaining with the way that initCommentForm
is creating its elements. I suspect that a malformed avatar url could
be used maliciously.

#5570

There are likely problems remaining with the way that initCommentForm is creating its elements. I suspect that a malformed avatar url could be used maliciously. #5570
Bwko (Migrated from github.com) approved these changes 2018-12-21 13:56:17 +00:00
adelowo approved these changes 2018-12-21 14:05:18 +00:00
This repo is archived. You cannot comment on pull requests.
No reviewers
No Milestone
No project
No Assignees
3 Participants
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: lunny/gitea#5575
No description provided.