osTicket v1.10 (stable) and Maintenance Release v1.9.15 are now available! Go get it now
Bug: Sanitzing with hmlawed, redactor and js > code tag in frontend is ignored and will be rendered
We know that security is an important fact in a public helpdesk. If you like to use osTicket as support system for software, web hosting etc. it's important that you can use in tickets, knowledgebase and pages the <code> tag with none interpreted code. To display code correctly between the code tages it's standard to use html entities.
The html entities are converted and interpreted by the osTicket sanitizing functions as running code. This will lead that e.g. <code><h1>Heading 1</h1></code> will be displayed as a formatted h1.
Please can you help us adjust this? Any hints are really welcome.