Skip to content

去除html编码中的空格,最后一行过滤会导致正常值【script】被过滤掉,建议删除#19

Open
copyboy wants to merge 1 commit intostylefeng:masterfrom
copyboy:master
Open

去除html编码中的空格,最后一行过滤会导致正常值【script】被过滤掉,建议删除#19
copyboy wants to merge 1 commit intostylefeng:masterfrom
copyboy:master

Conversation

@copyboy
Copy link

@copyboy copyboy commented Apr 18, 2018

XSS的这个过滤有点问题,建议使用commons-text包中的html转码

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant