Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SentEmailViewer allows HTML injection #536

Closed
nwessing opened this issue May 24, 2020 · 1 comment · Fixed by #548
Closed

SentEmailViewer allows HTML injection #536

nwessing opened this issue May 24, 2020 · 1 comment · Fixed by #548
Labels
more-info Needs more information.

Comments

@nwessing
Copy link

When rendering a text email, the SentEmailViewer will not escape the contents properly, allowing any markup in the email to be rendered as is.

@germsvel
Copy link
Collaborator

Hi @nwessing, thanks for bringing this up. Do you have any examples that I could use to reproduce this?

@germsvel germsvel added the more-info Needs more information. label Aug 12, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
more-info Needs more information.
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants