Problems sanitizing image titles
|Reported by:||bi0xid||Owned by:|
If you upload an image in any article, you can put a title to it. If this title has a >, it breaks the img tag and shows incorrectly (broken) when publishing.
In the editor, when editing an article, all images are shown, even if they are broken when published.
I have tried to exploit it, but " is sanitized to ", so this is not a serious problem.
Change History (8)
- Milestone changed from 3.2 to Future Release
- Priority changed from normal to low
- Severity changed from normal to minor