Menu

#15 Action "export settings": metadata strings not escaped

2.0
closed
Peter B.
2025-01-30
2025-01-30
Peter B.
No

Metadata strings are not escaped in the HTML forms UI in "export_settings" Action.
This causes the HTML form to break if any of these strings contain special characters.

TODO: Add htmlspecialchars() around the values.

Discussion

  • Peter B.

    Peter B. - 2025-01-30

    Fixed in revision #540.

     
  • Peter B.

    Peter B. - 2025-01-30
    • status: open --> closed
     

Log in to post a comment.

MongoDB Logo MongoDB