-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Description
$html="<div><p align='left' onclick='alert(1)'>sample <b><i>text</i></b><script type='text/javascript'>alert(2);</script></p></div>";
$allowed=array('b', 'p' => array('align'));
print sanitize($html,$allowed)."\n";
Expected: <p align="left">sample <b>text</b></p>
Actual: <p align="left">sample <b>text</b>alert(2);</p>
Metadata
Metadata
Assignees
Labels
No labels