Open julien-duponchelle opened 10 years ago
Actually you can inject HTML inside the status message, i think it should be escaped.
Actually you can inject HTML inside the status message, i think it should be escaped.