From fea12d9f57a0b8b457dcedd85302539ba5a9c642 Mon Sep 17 00:00:00 2001 From: Rolux Date: Fri, 8 Jan 2016 13:28:56 +0530 Subject: [PATCH] fix xss vuln --- static/js/infoView.js | 1 + 1 file changed, 1 insertion(+) diff --git a/static/js/infoView.js b/static/js/infoView.js index ec9ee0b..5129afe 100644 --- a/static/js/infoView.js +++ b/static/js/infoView.js @@ -115,6 +115,7 @@ oml.ui.infoView = function(identifyData) { function formatValue(value, key) { return value ? (Ox.isArray(value) ? value : [value]).map(function(value) { + value = Ox.encodeHTMLEntities(value); if (key == 'date' && value) { value = value.slice(0, 4); }