60983cfeee
This is a partial, perhaps temporary fix. "<", ">", and "&" characters in patron comments (AKA reviews) are converted to "<", ">", and "&" to avoid certain attacks, e.g., a user entering a <script> tag in a comment. A more permanent fix should scrub all (or perhaps just unsafe) tags from submitted comments entirely. Signed-off-by: Joshua Ferraro <jmf@liblime.com> |
||
---|---|---|
.. | ||
reviewswaiting.tmpl |