Is xss attack possible between html tag while < and > are encoded

Viewed 1590

Is xss attack possible between html tag while < and > are encoded? for example:

<tag>{{output}}</tag>

if "<", ">" in {{output}} are encoded into "&lt;", "&gt;", and <tag> cannot be <script>, can xss happen?

1 Answers
Related