Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

System administration should escape data #298

Open
joho1968 opened this issue May 31, 2023 · 3 comments
Open

System administration should escape data #298

joho1968 opened this issue May 31, 2023 · 3 comments

Comments

@joho1968
Copy link

joho1968 commented May 31, 2023

If I specify the string <a href="https:// åäö, this is cool!, the admin interface does not seem to work very well when I click on the Menu option. I think all output in the System administration section need to escape configuration option values, using htmlentities() or some other mechanism.

@joho1968
Copy link
Author

Having said that, my "trial theme" does precisely that and seem to break the Simple Blog plugin (in one distinct place).

@robiso
Copy link
Collaborator

robiso commented Nov 1, 2023

Hello @joho1968, when trying to reproduce the issue with a page named: "åäö, this is cool!", everything worked as expected, would you mind providing a screenshot of the issue?

@joho1968
Copy link
Author

joho1968 commented Nov 6, 2023

You need to enter the full HTML above: <a href="https:// åäö, this is cool! and then WonderCMS starts to behave somewhat erratically.

This is what I get when I'm in the Menu section of admin:

image

Unfortunately, it's very hard to take a screenshot after clicking on the "Edit" button for the field, but it contains a lot of strange HTML, etc.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants