Skip to content

Commit 0ffb73a

Browse files
JisanAR03DonnieBLT
authored andcommitted
fix security issue #1337
1 parent 27ee99c commit 0ffb73a

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

website/templates/report.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -407,7 +407,7 @@ <h2 class="text-2xl font-semibold leading-7 text-gray-900">
407407
let fileDiv = $("<div>").addClass("w-full md:w-[300px] h-[180px] overflow-hidden rounded-lg").attr("onclick", `previewFile('${safeName}')`);
408408
let titleDiv = $("<div>").addClass("w-full h-10 flex justify-center rounded-t-lg p-2 bg-gray-500");
409409
let titleP = $("<p>").addClass("text-xl text-white font-bold").text(safeNameDisplay);
410-
let img = $("<img>").addClass("object-cover").attr("src", src);
410+
let img = $("<img>").addClass("object-cover").attr("src", escapeHtml(src));
411411

412412
titleDiv.append(titleP);
413413
fileDiv.append(titleDiv).append(img);

0 commit comments

Comments
 (0)