DNN.Blog
DNN.Blog copied to clipboard
Comments are not HTML encoded
This leaves the commenting system open to XSS attacks and HTML injection.
Before saving a comment to the database, it should be encoded.