diff --git a/company/static/company/js/md_editor.js b/company/static/company/js/md_editor.js index d19feb2da..11ad345de 100644 --- a/company/static/company/js/md_editor.js +++ b/company/static/company/js/md_editor.js @@ -20,7 +20,7 @@ const olButton = document.querySelector('#list-ol'); preview.addEventListener('click', () => { - output(parse(textarea.value)); + output(escapeHTML(parse(textarea.value))); outputArea.classList.toggle('show'); previewMessage.classList.toggle('show'); @@ -302,10 +302,15 @@ function parse2(content) { content = content.replace(unorderedSubList, '