#15365: if the restructuredtext markup is meant to be safe (I cannot see 
anything
to say if it is or isn't... :/) ...
-----------------------------------+----------------------------------------
 Reporter:  db.pub.mail@…          |          Owner:  nobody    
   Status:  new                    |      Milestone:  1.3       
Component:  Contrib apps           |        Version:  1.2       
 Keywords:                         |   Triage Stage:  Unreviewed
Has patch:  0                      |  
-----------------------------------+----------------------------------------
 if the restructuredtext markup is meant to be safe (I cannot see anything
 to say if it is or isn't... :/)

 then the following demonstrates a potential issue:

 thingy/lol.html

 {% load markup %}
        {{LOL|restructuredtext}}

 views.py
 ...

 def index(request):
   return render_to_response('thingy/lol.html', {'LOL: "`NotMe
 <javascript:alert(1)>`_"})

-- 
Ticket URL: <http://code.djangoproject.com/ticket/15365>
Django <http://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

-- 
You received this message because you are subscribed to the Google Groups 
"Django updates" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/django-updates?hl=en.

Reply via email to