Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Ensure simple_format escapes its html attributes
The previous behavior equated the sanitize option for simple_format with the escape option of content_tag, however these are two distinct concepts. This fixes CVE-2013-6416
- Loading branch information