bu-navigation
bu-navigation copied to clipboard
Label Field allows HTML like an <iframe>, horrible results ensue
Client sent a bug:
Found this in the admin:
uh-oh.
Label field should probably sanitize HTML? Or at least only allow a limited subset... certainly not <iframe>