I was reading http://hackerific.net/2015/01/16/avoid-xss-in-template-toolkit/ Avoid XSS in Template Toolkit
and then it occured to me! Should you escape every place a template variable is used? I mean I have a site where you make a choice using a Jquery slider which is send to the server through AJAX POST, and then Template::Toolkit displays the value entered.
In essence there is no form POST where the user can enter data freely.But,can the user still manipulate the posted data and should I use escaping for the posted slider data? Shoudl I escape ALL data passed to Template toolkit or in certain cases ?
In reply to Template toolkit XSS by Anonymous Monk
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |