Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

HTML in the message should be escaped #104

Closed
benface opened this issue Oct 31, 2017 · 7 comments
Closed

HTML in the message should be escaped #104

benface opened this issue Oct 31, 2017 · 7 comments
Assignees
Labels

Comments

@benface
Copy link

benface commented Oct 31, 2017

Any HTML entered by the user in the message field is rendered raw in the email's body. I believe that's a security issue, and if not, it's just annoying. :P

@brandonkelly
Copy link
Member

Agree that should not be the case.

@brandonkelly
Copy link
Member

@benface What version of Craft & Contact Form are you using?

@benface
Copy link
Author

benface commented Oct 31, 2017

@brandonkelly Version 1.9.1 running on Craft CMS 2.6.2993.

angrybrad added a commit that referenced this issue Oct 31, 2017
@angrybrad
Copy link
Member

angrybrad added a commit that referenced this issue Nov 1, 2017
@benface
Copy link
Author

benface commented Feb 18, 2018

@angrybrad Still seeing this in version 2.1.1 running on Craft CMS 3.0.0-RC10.1.

@benface
Copy link
Author

benface commented Mar 24, 2018

@angrybrad Did you see this? Should I submit a new issue?

@angrybrad
Copy link
Member

@MakeilaLundy @Radabaugh this needs to be addressed for the v2 branch as well.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

5 participants