techknowlogick af4626a270 Immediate fix to htmlEncode user added text (#5575)
There are likely problems remaining with the way that initCommentForm
is creating its elements. I suspect that a malformed avatar url could
be used maliciously.
2018-12-21 09:05:47 -05:00
..
2017-11-21 06:26:43 +02:00
2018-09-06 21:15:25 -04:00