Welcome Guest, Not a member yet? Register   Sign In
Using xss_clean() for displaying content from WYSIWYG editor
#2

I guess that's why using meta-tags like [b] on forums is so popular - you can convert all < and > characters to &lt; / &gt; to avoid any script execution, then replace all meta-tags with actual HTML tags. Or Markdown is quite popular as well, but both use their own syntax, THEN convert to HTML.

I guess if it's stored in DB correctly, and it is xss_clean that replaced &lt; with < - you could replace &lt; with -my-random-less-than-replacement- before xss_clean, then revert it back. Quite ugly solution, but could get you going.
Reply


Messages In This Thread
RE: Using xss_clean() for displaying content from WYSIWYG editor - by Pertti - 08-13-2018, 12:59 AM



Theme © iAndrew 2016 - Forum software by © MyBB