Kaydet (Commit) 5dbe2a94 authored tarafından Tim Graham's avatar Tim Graham

Fixed #4991 -- Emphasized XSS ramifications of help_text not being escaped.

üst 15cafaa5
......@@ -260,7 +260,9 @@ desire. For example::
help_text="Please use the following format: <em>YYYY-MM-DD</em>."
Alternatively you can use plain text and
``django.utils.html.escape()`` to escape any HTML special characters.
``django.utils.html.escape()`` to escape any HTML special characters. Ensure
that you escape any help text that may come from untrusted users to avoid a
cross-site scripting attack.
``primary_key``
---------------
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment