bu-navigation
bu-navigation copied to clipboard
Label Field allows HTML like an <iframe>, horrible results ensue
trafficstars
Client sent a bug:

Found this in the admin:

uh-oh.
Label field should probably sanitize HTML? Or at least only allow a limited subset... certainly not <iframe>

https://buweb.slack.com/archives/C08LCBE3D/p1643917410133739
Probably adjusting this line would work:
https://github.com/bu-ist/bu-navigation/blob/9c9ff6569ed4560104cf40395cdc82a6d25cfe09/admin/post.php#L230