Update index.js, fix outgoing XSS

Fix XSS on /outgoing route
v1.18.x
Mikica Ivosevic 10 years ago
parent cead53ec86
commit e24bd2c0e3

@ -181,7 +181,7 @@ Controllers.robots = function (req, res) {
Controllers.outgoing = function(req, res, next) { Controllers.outgoing = function(req, res, next) {
var url = req.query.url, var url = req.query.url,
data = { data = {
url: url, url: validator.escape(url),
title: meta.config.title, title: meta.config.title,
breadcrumbs: helpers.buildBreadcrumbs([{text: '[[notifications:outgoing_link]]'}]) breadcrumbs: helpers.buildBreadcrumbs([{text: '[[notifications:outgoing_link]]'}])
}; };

Loading…
Cancel
Save