the template don't escape the html inside itself
Hello,
the template system doesn't escape the html inside itself, it can be dangerous and a security problem, that should be fixed
Cheers
(from redmine: issue id 2140, created on 2013-03-18, closed on 2013-04-17)
- Changesets:
- Revision bcc24281 by Côme Chilliet on 2013-03-18T15:16:12.000Z:
Fixes: #2140 the template don't escape the html inside itself
- Custom Fields:
- Bug in version: 1.0.5
- Uploads: