Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Fixed
-
1.4.2
-
None
-
None
Description
This was discovered when encountering CONTINUUM-2762 on continuum-ci.a.o. One of the commit messages contained an HTML input tag, which was apparent when visiting the page since focus was forced to it. Messages should be escaped for safe display to a web browser to prevent this.
Attachments
Attachments
Issue Links
- duplicates
-
CONTINUUM-1983 unescaped HTML in SCM Changes summary
- Closed