[wp-trac] [WordPress Trac] #58303: Found Escaping Issue While Echoing Attribute Dynamic Value in HTML Attribute.
WordPress Trac
noreply at wordpress.org
Sat May 13 13:08:12 UTC 2023
#58303: Found Escaping Issue While Echoing Attribute Dynamic Value in HTML
Attribute.
----------------------------+-------------------------------
Reporter: mahamudur78 | Owner: (none)
Type: defect (bug) | Status: new
Priority: normal | Milestone: Awaiting Review
Component: Administration | Version:
Severity: normal | Resolution:
Keywords: has-patch | Focuses: coding-standards
----------------------------+-------------------------------
Comment (by SergeyBiryukov):
Hi there, welcome to WordPress Trac! Thanks for the ticket.
The `$columns` variable goes through `absint()` and is not user-editable,
so it does not currently require escaping, though it might be preferable
to add the escaping as a defensive coding measure.
This is indeed similar to [54857] / #57133, but there is also an ongoing
discussion in comment:17:ticket:58251 on whether it is a good idea to
preventively add escaping in cases like this.
--
Ticket URL: <https://core.trac.wordpress.org/ticket/58303#comment:3>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform
More information about the wp-trac
mailing list