I have an admin block on my site in which users edit information about themselves. And there is a text field to which I attached the editor (TINYMCE), but it turns out that all tags work correctly htmlspecialchars no longer apply.
And accordingly, from this the possibility appeared that the user could enter some kind of script and run it ...
How to be in this case?