[wp-trac] [WordPress Trac] #12181: Sanitizing text input fields before rendering but not before storing their content

WordPress Trac wp-trac at lists.automattic.com
Tue Feb 9 11:19:14 UTC 2010


#12181: Sanitizing text input fields before rendering but not before storing their
content
------------------------------+---------------------------------------------
 Reporter:  hargatheterrible  |       Owner:                   
     Type:  defect (bug)      |      Status:  new              
 Priority:  normal            |   Milestone:  Unassigned       
Component:  General           |     Version:  2.9.1            
 Severity:  normal            |    Keywords:  reporter-feedback
------------------------------+---------------------------------------------
Changes (by dd32):

  * keywords:  sanitize filter => reporter-feedback


Comment:

 Can you post some code to highlight the bug you're seeing?

 Also, verify that YOU are escaping the data before echoing it into a
 attribute using a function such as {{{esc_attr()}}}

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/12181#comment:1>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list