Welcome Guest! To enable all features please Login or Register.

Notification

Icon
Error

Html report for console test runner is not escaping html in test case
GreenMoose
#1 Posted : Wednesday, September 3, 2014 7:02:46 AM(UTC)
Rank: Advanced Member

Groups: Registered
Joined: 6/17/2012(UTC)
Posts: 503

Thanks: 142 times
Was thanked: 66 time(s) in 64 post(s)
v2.9.0.3

So I have a NUnit test case with a string containing "<script>alert(123);</script>", this is not escaped in html output so when I open the AllResults.html I get these alerts executed.
Remco
#2 Posted : Wednesday, September 3, 2014 7:07:49 AM(UTC)
Rank: NCrunch Developer

Groups: Administrators
Joined: 4/16/2011(UTC)
Posts: 6,979

Thanks: 931 times
Was thanked: 1257 time(s) in 1170 post(s)
Ouch! Thanks for the heads up. I'll get that fixed.
Users browsing this topic
Guest
Forum Jump  
You cannot post new topics in this forum.
You cannot reply to topics in this forum.
You cannot delete your posts in this forum.
You cannot edit your posts in this forum.
You cannot create polls in this forum.
You cannot vote in polls in this forum.

YAF | YAF © 2003-2011, Yet Another Forum.NET
This page was generated in 0.017 seconds.
Trial NCrunch
Take NCrunch for a spin
Do your fingers a favour and supercharge your testing workflow
Free Download