displayname of the user can contain HTML tags and the string is not filtered in some views #11705
Labels
Priority:p2-high
Escalation, on top of current planning, release blocker
Type:Bug
Something isn't working
Describe the bug
The string from 'first and lastname' of a user are shown unfiltered in the notifications
Luckily only the admin can set that data
Steps to reproduce
einstein
to<a href="http://jankari.tech">einstein</a>
einstein
share a folder tomarie
marie
check the notificationsExpected behavior
the HTML string should be encoded as e.g. the sharing dialog
Actual behavior
a link is rendered in the notifications
Setup
The text was updated successfully, but these errors were encountered: