No HTML quoting of address on "Subscription results" page
Bug #265991 reported by
Peter Moulder
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
GNU Mailman |
New
|
Medium
|
Unassigned |
Bug Description
When subscribing using the web interface (e.g.
http://
the resulting "mylist Subscription results" page
includes the literal text "<email address hidden>"
("Instructions are being sent to you at
<email address hidden>"), whereas HTML contains no such
element. Subscriber address ought to be html-escaped
using <, >, &.
(Also, as mentioned in #596215, this page contains
other bad HTML such as an unterminated "<body" tag, and
a <html>...</html> element within a <BODY
...>...</body> element.)
version 2.0.9-sf.net
pjrm.
[http://
To post a comment you must log in.