Merge pull request #3371 from mikicaivosevic/patch-1

Update index.js, fix outgoing XSS
v1.18.x
Barış Soner Uşaklı 10 years ago
commit 924692404d

@ -181,7 +181,7 @@ Controllers.robots = function (req, res) {
Controllers.outgoing = function(req, res, next) { Controllers.outgoing = function(req, res, next) {
var url = req.query.url, var url = req.query.url,
data = { data = {
url: url, url: validator.escape(url),
title: meta.config.title, title: meta.config.title,
breadcrumbs: helpers.buildBreadcrumbs([{text: '[[notifications:outgoing_link]]'}]) breadcrumbs: helpers.buildBreadcrumbs([{text: '[[notifications:outgoing_link]]'}])
}; };

Loading…
Cancel
Save