Closed theilm closed 4 years ago
In order to prevent XSS, preview output should be html escaped.
Ain't that a bugfix?
ah, too late :)
In order to prevent XSS, preview output should be html escaped.