Fix JS injection vulnerability and test case