Skip to content

Sanitizer does not handle certain html string #579

@deepakageeru

Description

@deepakageeru

var sanitizer = new HtmlSanitizer();
var html = @"<<img>svg onload=alert(document.domain)>";
var sanitized = sanitizer.Sanitize(html, "http://www.example.com");
Console.WriteLine(sanitized); // returns "&lt;<img>svg onload=alert(document.domain)&gt;"

Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions