Menu

#9 Escape quotes in attribute values

Beta
pending
security (2)
2012-09-26
2012-06-18
Psion Ski
No

Element attribute values shouldn't contain quotes. Look for a proven method to sanitize them (xml.sax.saxutils.quoteattr in Python?) and implement it.

Discussion

  • Psion Ski

    Psion Ski - 2012-09-26
    • status: open --> pending
    • assigned_to: Vladislav Zorov
     
  • Psion Ski

    Psion Ski - 2012-09-26

    We already escape attribute values in this fashion. There still exists a possible attack vector, which is visible as a failed test in the current version of the code.

     

Log in to post a comment.

Want the latest updates on software, tech news, and AI?
Get latest updates about software, tech news, and AI from SourceForge directly in your inbox once a month.