v1.18.x
Barış Soner Uşaklı 8 years ago
parent d171f4049d
commit 1eddf4c720

@ -1,7 +1,8 @@
"use strict"; "use strict";
var async = require('async'); var async = require('async');
var validator = require('validator');
var db = require('../../database'); var db = require('../../database');
var groups = require('../../groups'); var groups = require('../../groups');
var user = require('../../user'); var user = require('../../user');
@ -204,7 +205,7 @@ User.search = function(socket, data, callback) {
userData.forEach(function(user, index) { userData.forEach(function(user, index) {
if (user && userInfo[index]) { if (user && userInfo[index]) {
user.email = userInfo[index].email || ''; user.email = validator.escape(String(userInfo[index].email || ''));
user.flags = userInfo[index].flags || 0; user.flags = userInfo[index].flags || 0;
} }
}); });

Loading…
Cancel
Save