Velocity does not automatically escape HTML entities when substituting variables

XMLWordPrintable

      Velocity should automatically escape (encode) HTML entities in variables it interpolates in markup. This would remove the need for explicitly escaping variables using $generalUtil.htmlEncode, and fix lots of XSS bugs including ones we haven't discovered yet.

      This affects all versions of Confluence.

              Assignee:
              Christopher Owen [Atlassian]
              Reporter:
              Matt Ryall
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: