<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
	<title>jQuery Grid Plugin - jqGrid - Topic: XSS for inline editing with autoencode</title>
	<link>http://www.trirand.com/blog/?page_id=393/help/xss-for-inline-editing-with-autoencode</link>
	<description><![CDATA[Grid plugin]]></description>
	<generator>Simple:Press Version 5.7.5.3</generator>
	<atom:link href="http://www.trirand.com/blog/?page_id=393/help/xss-for-inline-editing-with-autoencode/rss" rel="self" type="application/rss+xml" />
        <item>
        	<title>tony on XSS for inline editing with autoencode</title>
        	<link>http://www.trirand.com/blog/?page_id=393/help/xss-for-inline-editing-with-autoencode#p30935</link>
        	<category>Help</category>
        	<guid isPermaLink="true">http://www.trirand.com/blog/?page_id=393/help/xss-for-inline-editing-with-autoencode#p30935</guid>
        	        	<description><![CDATA[<p>Hello,</p>
<p>Â </p>
<p>depending on the editing module you can use serializeEditData to make the conversion, before it is posted to the server</p>
<p>Â </p>
<p>Regards</p>
]]></description>
        	        	<pubDate>Mon, 11 Aug 2014 14:03:07 +0300</pubDate>
        </item>
        <item>
        	<title>dk on XSS for inline editing with autoencode</title>
        	<link>http://www.trirand.com/blog/?page_id=393/help/xss-for-inline-editing-with-autoencode#p30925</link>
        	<category>Help</category>
        	<guid isPermaLink="true">http://www.trirand.com/blog/?page_id=393/help/xss-for-inline-editing-with-autoencode#p30925</guid>
        	        	<description><![CDATA[<p>Hi all,Â </p>
<p>I am working on inline editing in jqGrid, and wanted to escape wherever the html is getting executed. I can't use autoencode for now due to the way different consumers are using the grid code. Could you please point me out in the jqgrid code where to escape the html so it does not executeÂ code like this when entered through inline editing:Â </p>
<p>&#60;img src=a onerror=alert(1)&#62;</p>
<p>Thanks!!</p>
]]></description>
        	        	<pubDate>Tue, 05 Aug 2014 04:06:05 +0300</pubDate>
        </item>
</channel>
</rss>