hugo-plus-staticman icon indicating copy to clipboard operation
hugo-plus-staticman copied to clipboard

Basic html escape in hugo for simple xss prevention

Open s3gm3nt4ti0nf4ult opened this issue 4 years ago • 0 comments

Putting unsanitized HTML entities into source code could lead to XSS by creating a malicious comment. The impact of XSS on static site is not as high as it could be in other cases, but it's worth noting. Probably staticman should do someting about XSS and entities encoding?

s3gm3nt4ti0nf4ult avatar Aug 04 '20 09:08 s3gm3nt4ti0nf4ult