Skip to content

Output improperly sanitized #56

@bramz

Description

@bramz

Describe the bug
Some characters are being rendered allowing uploaded content to inject or render data on the page.

To Reproduce
http://cdn.paste.click/ZJ2qGKLleIoaDRRbkVp5GQ

Expected behavior
Should render simple plain text with all characters properly escaped/sanitized.

Screenshots
https://cdn.discordapp.com/attachments/523599882162929664/549847817078702080/unknown.png

Metadata

Metadata

Labels

bugSomething isn't working

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions