HTML: Should I encode greater than or not? ( > > )

后端 未结 6 689
梦如初夏
梦如初夏 2020-12-05 09:20

When encoding possibly unsafe data, is there a reason to encode >?

  • It validates either way.
  • The browser interprets the same either way
6条回答
  •  余生分开走
    2020-12-05 09:53

    Yes, because if signs were not encoded, this allows xss on forms social media and many other because a attacker can use

提交回复
热议问题