The htmlspecialchars function does not 100% prevent XSS.
The htmlspecialchars () function only translates the &,', ", and symbols into html special symbols.
We can use url coding to perform * on tags with connections:
The htmlspecialchars () function only translates the &,', ", and symbols into html special symbols.
We can use url coding to perform * on tags with connections: