Skip to content
Snippets Groups Projects
Commit e1fa9c28 authored by Björn Schießle's avatar Björn Schießle
Browse files

xss vulnerabilities fixed

parent 033d372f
Branches
No related tags found
No related merge requests found
......@@ -168,7 +168,7 @@ class TileStack extends TileBase {
}
public function getOnClickAction() {
return 'javascript:openNewGal(\''.$this->stack_name.'\');';
return 'javascript:openNewGal(\''.\OCP\Util::sanitizeHTML($this->stack_name).'\');';
}
private $tiles_array;
......
<script type="text/javascript">
var root = "<?php echo $_['root']; ?>";
var root = "<?php echo OCP\Util::sanitizeHTML($_['root']); ?>";
$(document).ready(function() {
$("a[rel=images]").fancybox({
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment