Special characters in caption lead to failure of inserting images
|Reported by:||TobiasBg||Owned by:|
Found this when double-checking #22132:
- Go to add a new post.
- Click "Upload/Insert" (the "old" media upload).
- Upload an image, or go to choose one from the media library.
- Insert Title"<script>alert('Title');</script> in the "Caption" field.
- Click "Insert into Post".
Instead of the image (or Shortcode) being added to the editor (with a somehow escaped caption field), the media upload iframe just gets a new content:
[/caption]'); /* ]]> */
Reproduced in 3.4.2 and trunk.
Change History (4)
Note: See TracTickets for help on using tickets.