Problem/Motivation

It was agreed that security issue #180347 can be handled in public. User input for address fields not filtered in preview.

Proposed resolution

Render the content with #plain_text instead of #markup.

Remaining tasks

Implement.

User interface changes

None.

API changes

None.

Data model changes

None.

Issue fork webform-3592565

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

liam morland created an issue. See original summary.

liam morland’s picture

Version: 6.3.x-dev » 6.2.x-dev
Status: Active » Needs review
liam morland’s picture

Status: Needs review » Needs work

This change is causing test failures.