hunt-framework / hayoo

Hackage search engine
56 stars 9 forks source link

HTML is not properly escape #46

Open jprider63 opened 9 years ago

jprider63 commented 9 years ago

HTML in documentation is not properly escaped, which is an injection issue. You can see this by searching for textarea.