-
Type: Bug
-
Status: Closed (View Workflow)
-
Priority: Minor
-
Resolution: Won't Fix
-
Affects Version/s: 2.5 Larks
-
Fix Version/s: 2.6 Larks
-
Labels:
-
Sprint:2.6 Larks
Preconditions
User has admin permissions, is logged in, is in admin mode
Steps to reproduce
1. Go to external links editor - press "Add"
2. Fill all fields with
<script>alert("Hi")</script>
3. Press "Save" button, close external links editor.
Actual result
Just added link has following code:
<li><a id="small-screen-external-link-9696" data-original-title="<script>alert("Hi")</script>" href="http://<script>alert("Hi")</script>"><script>alert("Hi")</script></a></li>
I.e. > is escaped, " is transformed, / is not transformed.
Expected result
All special symbols (including slashes, backslashes, quotes and so on) in external link should be encoded equally.
So if we use escaping - all special symbols should be escaped (without using something like ").