HtmlSanitizer
HtmlSanitizer copied to clipboard
Sanitizer does not handle certain html string
var sanitizer = new HtmlSanitizer();
var html = @"<<img>svg onload=alert(document.domain)>";
var sanitized = sanitizer.Sanitize(html, "http://www.example.com");
Console.WriteLine(sanitized); // returns "<<img>svg onload=alert(document.domain)>"
Looks fine to me at first glance. What output do you expect?