Filter/Forwarders html encode errors (SECURITY):low

Version 1.60.2


User is able to provide invalid characters in some cases to inject their own results with arbitrary JS. The threat level is essentially zero as the XSS protection would work correctly, so it can only be self inflicted, but a bug nonetheless. Credit: Bartosz Kwitniewski

