Opened 4 years ago
Closed 4 years ago
#9322 closed defect (bug) (fixed)
Post/Page titles aren't fully escaped
| Reported by: |
|
Owned by: |
|
|---|---|---|---|
| Priority: | normal | Milestone: | 2.8 |
| Component: | Administration | Version: | 2.8 |
| Severity: | normal | Keywords: | has-patch needs-testing |
| Cc: |
Description
To reproduce:
- Write a post called "I <3 WordPress". Note you cannot use "<" as HTML is currently allowed in post titles (<del> for example is a valid usage).
- Save or Publish the post. You'll notice the title of the post is now "I <3 WordPress". This is incorrect and will break things if you save again.
Attached patch fully escapes all post titles.
Attachments (2)
Change History (6)
Viper007Bond — 4 years ago
comment:1
Viper007Bond — 4 years ago
Viper007Bond — 4 years ago
comment:2
Viper007Bond — 4 years ago
There, working as intended now (I think).
Note: See
TracTickets for help on using
tickets.

Bad patch. Quotes and things now improperly get escaped.