If RemoveXSS extension is enabled, “&” will be converted to “&” on form submission, the confirm page shows the values to be saved. If you don’t want such conversion, you may set the field as Raw by the RemoveXSS extension.
ok, i’d prefer to keep it on, but is there any way to show the actual characters on the submit/confirm stage, but still write out as the XSS code?
you know how users are if they start seeing these odd characters, they’ll think something is incorrect