vestman / Select-or-Die

Yet another jQuery plugin to style select elements. Demo at http://vst.mn/selectordie/
MIT License
524 stars 133 forks source link

Grabbing the text unescapes any escaped html. Grab the html. #30

Open darfire opened 9 years ago

darfire commented 9 years ago

Try having the text of an option element as something like &lt;script&gt;alert(11)&lt;/script&gt; (<script>alert(11)</script> escaped). When you take $optionText with text() you get the unescaped content. When you set it later on the span.sod_option using html() you're basically undoing the escaping. This fixes it by keeping the escaped content.