Comment 2 for bug 1807872

Revision history for this message
Akihiro Motoki (amotoki) wrote :

NOTE: If someone would like to fix it, you need to consider risk of script injection in other delete forms and other templates carefully.

IMHO this issue is super low-hanging-fruit and very low because it is not common to use such character as username.