php - WYSIWYG editor security question (preventing malicious input) -


I am using jWYSIWYG in a form, I am making that post in the database and wondering if you How can a malicious user try to inject the code into the frame?

Does the editor need a bracket to display styles (which I normally used to bar during the post process)?

I have encountered similar situations, and I started using it on my PHP backend That which can stop the vector of each attack which I can think of. It's easy to set up, and will allow you to whitelist the elements and attributes. It also prevents XSS attacks which can still exist using htmlentities.


Comments

Popular posts from this blog

windows - Heroku throws SQLITE3 Read only exception -

lex - Building a lexical Analyzer in Java -

python - rename keys in a dictionary -