Actions
Bug #5485
closedERB html_escape should follow OWASP recommendations
Description
Hi,
OWASP recommends that we escape single quotes and forward slashes before inserting them in to HTML. I would like to change ERB::Util.html_escape to do that.
I've attached a patch. Thanks!
Files
Actions
Like0
Like0Like0