From f46110cf77535ee5674e1dd30e706549bf24881f Mon Sep 17 00:00:00 2001 From: Valentin Dudouyt Date: Mon, 9 Jan 2017 15:19:03 +0700 Subject: [PATCH] Security improvement: taking textarea.value is risky due to HTML entities interpretation --- nicEdit.js | 1 - 1 file changed, 1 deletion(-) diff --git a/nicEdit.js b/nicEdit.js index c52b79f..77d8610 100755 --- a/nicEdit.js +++ b/nicEdit.js @@ -594,7 +594,6 @@ var nicEditorInstance = bkClass.extend({ editorElm.innerHTML = e.innerHTML; if (isTextarea) { - editorElm.setContent(e.value); this.copyElm = e; var f = e.parentTag('FORM'); if (f) {