Skip to content
Snippets Groups Projects
Commit 91f69858 authored by Björn Schießle's avatar Björn Schießle
Browse files

escape log messages to avoid possible js execution

parent e5feb4e1
No related branches found
No related tags found
No related merge requests found
......@@ -39,7 +39,7 @@ OC.Log={
row.append(appTd);
var messageTd=$('<td/>');
messageTd.text(entry.message);
messageTd.text(entry.message.replace(/</, "&lt;").replace(/>/, "&gt;"));
row.append(messageTd);
var timeTd=$('<td/>');
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment