2
0
Эх сурвалжийг харах

[Web] escapehtml in mailbox.js (#4604)

Co-authored-by: FreddleSpl0it <patschul@posteo.de>
Niklas Meyer 3 жил өмнө
parent
commit
1edd4012e4

+ 2 - 1
data/web/js/site/mailbox.js

@@ -553,6 +553,7 @@ jQuery(function($){
               '</div>';
               '</div>';
             item.chkbox = '<input type="checkbox" data-id="resource" name="multi_select" value="' + encodeURIComponent(item.name) + '" />';
             item.chkbox = '<input type="checkbox" data-id="resource" name="multi_select" value="' + encodeURIComponent(item.name) + '" />';
             item.name = escapeHtml(item.name);
             item.name = escapeHtml(item.name);
+            item.description = escapeHtml(item.description);
           });
           });
         }
         }
       }),
       }),
@@ -1022,7 +1023,7 @@ jQuery(function($){
             if (!item.exclude > 0) {
             if (!item.exclude > 0) {
               item.exclude = '-';
               item.exclude = '-';
             } else {
             } else {
-              item.exclude  = '<code>' + item.exclude + '</code>';
+              item.exclude  = '<code>' + escapeHtml(item.exclude) + '</code>';
             }
             }
             item.server_w_port = escapeHtml(item.user1) + '@' + item.host1 + ':' + item.port1;
             item.server_w_port = escapeHtml(item.user1) + '@' + item.host1 + ':' + item.port1;
             item.action = '<div class="btn-group footable-actions">' +
             item.action = '<div class="btn-group footable-actions">' +