Select-or-Die icon indicating copy to clipboard operation
Select-or-Die copied to clipboard

Grabbing the text unescapes any escaped html. Grab the html.

Open darfire opened this issue 9 years ago • 0 comments

Try having the text of an option element as something like &lt;script&gt;alert(11)&lt;/script&gt; (<script>alert(11)</script> escaped). When you take $optionText with text() you get the unescaped content. When you set it later on the span.sod_option using html() you're basically undoing the escaping. This fixes it by keeping the escaped content.

darfire avatar Mar 09 '15 22:03 darfire