Menu

#2 query suggestions not escaped as anchors

open
nobody
5
2011-09-29
2011-09-29
No

Query suggestions in /emse/suggestions are depicted as hrefs, but not escaped. E.g. if "&" is in the suggestion, the server will interpret is as a URL argument.

Discussion


Log in to post a comment.

MongoDB Logo MongoDB