views:

38

answers:

0

How to avoid the wmd editor's js injection?

Code like below:

<

a href="http://www.abc.com"&gt;abc&lt;/a&gt;

<br />

<script>alert('hello')</script>