Menu

#20 security issue

open
nobody
None
5
2003-08-04
2003-08-04
No

There is a security issue that the profile information
is not escaped. I can include HTML which is a bad
thing. Suggested Fix, use HTMLEditFormat(Field, -1)
when you output the data.

Discussion


Log in to post a comment.

MongoDB Logo MongoDB