Escaping '<' and '>' in attributes – how it helps protect against mutation XSS
Summary
Google's Bug Hunters explain why the HTML standard now escapes angle brackets in attribute values and how this change helps prevent mutation XSS (mXSS) attacks.
- Published
- Collected
Skip to content