Is Markdown (with strip_tags) sufficient to stop XSS attacks?

后端 未结 7 1086
温柔的废话
温柔的废话 2020-12-16 01:31

I\'m working on a web application that allows users to type short descriptions of items in a catalog. I\'m allowing Markdown in my textareas so users can do some HTML format

7条回答
  •  佛祖请我去吃肉
    2020-12-16 02:17

    BBcode provides more safety because you are generating the tags.

    If is allowed, this will go straight through strip_tags ;) Bam !

提交回复
热议问题