﻿id	summary	reporter	owner	description	type	status	component	version	severity	resolution	keywords	cc	stage	has_patch	needs_docs	needs_tests	needs_better_patch	easy	ui_ux
5880	"Cross-site(?) scripting when adding text via the ""foreign key"" popup window"	roland.illig@…	nobody	"When I entered the following text into a text field, a JavaScript message box popped up:

    </script><script>alert('foo');</script>

You need to encode the ""</script>"" to prevent this from happening.
"		closed	contrib.admin	dev		fixed			Accepted	1	0	0	0	0	0
