-
☆ A M B ☆
- 450 Posts
I typed a <script> tag into the description of one of my TVs - not to try to do something crazy, but just as informative text (I didn’t really think much about it, but I guess I figured the tags would be converted to < etc.).
Instead it caused some sort of weird parsing problem. The result was that on a resource that used a template with that TV, the TV category tabs disappeared... all of the TVs displayed in one long list. Also, the description for that TV truncated where the <script> tag was.
This seems rather prone to disaster; someone could do some pretty wiggy stuff to happen in the Manager interface by typing HTML characters in to description fields.
Should Revolution be escaping html tags in descriptions?