TextValidator is insecure
The TextValidator currently allows strings like
%3cspan style="color: #BBBBBB;"%3ea nice text%3c/span%3e
It seems like we can't solve this completely with filter_var because then characters like percent, semikolon, quotes etc. can't be used in a text. In general the test case lacks realistic string which should pass the validator.
Updated by Christian Müller over 9 years ago
- Status changed from Accepted to Rejected
- Assignee deleted (
The test improvements are in review now, I will close this, we could decide to deprecate the TextValidator at some point. I added also some longer comment to the TextValidator to point out that it won't make sure the validated string is secure in all possible output environments.