Notifications
Clear all

[Solved] html entities

7 Posts
2 Users
1 Reactions
2,126 Views
(@maor44)
Active Member
Joined: 6 years ago
Posts: 5
Topic starter  

Hello, 

I'm using the plugin and notice that when user leave a comment like this 

<img src="image.gif" onerror="alert('1')">
the js code is run. 
 
what can we do? 

   
Quote
Astghik
(@astgh)
Illustrious Member Admin
Joined: 7 years ago
Posts: 6191
 

Hi maor44,

Could you please leave the example URL to allow us to check it? 


   
ReplyQuote
(@maor44)
Active Member
Joined: 6 years ago
Posts: 5
Topic starter  

it's problem because we can't upload it to the website until we fix it. 

but if you write this as a comment 

<img src="image.gif" onerror="alert('1')">

you will see the problem after the comment is approved.

This post was modified 6 years ago by maor44

   
ReplyQuote
Astghik
(@astgh)
Illustrious Member Admin
Joined: 7 years ago
Posts: 6191
 

@maor44,

Could you please check the same here comment: https://wpdiscuz.com/demo/


   
ReplyQuote
(@maor44)
Active Member
Joined: 6 years ago
Posts: 5
Topic starter  

http://prntscr.com/lkou5m

when I tried to write I get this error.


   
ReplyQuote
Astghik
(@astgh)
Illustrious Member Admin
Joined: 7 years ago
Posts: 6191
 

Hi @maor44,

Please watch this video. It seems you haven't filled some field in the comment form. 

https://www.screencast.com/t/vAdAmZaj


   
maor44 reacted
ReplyQuote
(@maor44)
Active Member
Joined: 6 years ago
Posts: 5
Topic starter  

Ok, now everything is working. don't know why.


   
ReplyQuote
Share:
Scroll to top