Przeglądaj źródła

Update base.twig to escape simple quote

Update base.twig to escape simple quote
See issue https://github.com/mailcow/mailcow-dockerized/issues/4718
Romain 2 lat temu
rodzic
commit
623397d20a
1 zmienionych plików z 1 dodań i 1 usunięć
  1. 1 1
      data/web/templates/base.twig

+ 1 - 1
data/web/templates/base.twig

@@ -172,7 +172,7 @@ function recursiveBase64StrToArrayBuffer(obj) {
     // TFA, CSRF, Alerts in footer.inc.php
     // Other general functions in mailcow.js
     {% for alert_type, alert_msg in alerts %}
-    mailcow_alert_box('{{ alert_msg|raw }}', '{{ alert_type }}');
+    mailcow_alert_box('{{ alert_msg|raw|e("js") }}', '{{ alert_type }}');
     {% endfor %}
 
     // Confirm TFA modal