From 40f131a6bb1ca0bc71f3fe230c15bdee972467bd Mon Sep 17 00:00:00 2001 From: Andrew Rodrigues Date: Thu, 26 Sep 2019 14:00:01 -0400 Subject: [PATCH] fix: potential for XSS here --- public/src/utils.js | 1 + 1 file changed, 1 insertion(+) diff --git a/public/src/utils.js b/public/src/utils.js index dde7096914..60f27fed71 100644 --- a/public/src/utils.js +++ b/public/src/utils.js @@ -691,6 +691,7 @@ }, urlToLocation: function (url) { + url = encodeURI(url); return $('')[0]; },