[pmwiki-users] Is ability to insert HTML a bug?

ljb ljb220 at mindspring.com
Sun Apr 2 19:46:58 CDT 2006


Two meta-questions, please: I came across a way a PmWiki-2.1.5 user can
insert any bit of HTML into a wiki page and have it returned to the browser
without escaping.  Is this a bug? (I think it probably is.) Is this a serious,
security-type bug? (I think it isn't, but PmWikiPhilosophy says it can be.)
So should I give details and a patch here, on PITS, or some other way?





More information about the pmwiki-users mailing list