HTML-encoding lost when attribute read from input field

前端 未结 25 3843
时光说笑
时光说笑 2020-11-21 04:04

I’m using JavaScript to pull a value out from a hidden field and display it in a textbox. The value in the hidden field is encoded.

For example,



        
25条回答
  •  耶瑟儿~
    2020-11-21 04:42

    ';
    console.log(aString.htmlEncode());
    
    

    Will output: <script>alert("I hack your site")</script>

    .htmlEncode() will be accessible on all strings once defined.

提交回复
热议问题