diff --git a/docs/topics/security.txt b/docs/topics/security.txt
index a3e656557b..6eab39efed 100644
--- a/docs/topics/security.txt
+++ b/docs/topics/security.txt
@@ -31,11 +31,11 @@ protect the following:
.. code-block:: html+django
-
+
If ``var`` is set to ``'class1 onmouseover=javascript:func()'``, this can result
in unauthorized JavaScript execution, depending on how the browser renders
-imperfect HTML.
+imperfect HTML. (Quoting the attribute value would fix this case.)
It is also important to be particularly careful when using ``is_safe`` with
custom template tags, the :tfilter:`safe` template tag, :mod:`mark_safe