Comment 3 for bug 1417762

Revision history for this message
Paul McMillan (paul-mcmillan) wrote :

If the output is rendered without escaping as innerhtml, it could certainly be an issue. I haven't had a chance to look at this issue in detail yet, but just because it's json doesn't mean it's not used inappropriately further down the line.