rails_xss
rails_xss copied to clipboard
link_to text not being escaped
The text part of link_to is not being escaped when it's not a safe string. The following snippet triggers a popup:
<%= link_to "<script>alert(\"XSS!!!\")</script>", nil %>
Thanks.
This was fixed on github.com/rails/rails_xss but this version will be usable with Rails 2.3.6
Can it be backported? Would it be merged back into NZKoz/rails_xss if I backport it?
Yes it will be backported, don't worry we are fixing a couple of thing and we will do that sooner, thank you for helping.