esotalk / esoTalk

Fat-free forum software.
GNU General Public License v2.0
1.47k stars 239 forks source link

FIX: XSS bug #379

Closed ghost closed 9 years ago

ghost commented 9 years ago

Called htmlentities on value of textarea to prevent XSS injection. Example: Someone creates a post with