Security risks from user-submitted HTML

后端 未结 4 1829
长情又很酷
长情又很酷 2021-01-21 07:22

I am using a contentEditable div that allows users to edit the body HTML and then post it directly to site using an AJAX request. Naturally, I have to do some security checks o

4条回答
  •  时光取名叫无心
    2021-01-21 07:49

    Javascript can be called any number of ways by using the event attributes on elements, like:

    
    

    A similar question posted here recommends using HTMLPurifier instead of trying to handle this on your own.

提交回复
热议问题