]> source.dussan.org Git - sonarqube.git/commitdiff
SSF-21 XSS vulnerability on Measures page
authorStas Vilchik <vilchiks@gmail.com>
Wed, 15 Oct 2014 13:33:35 +0000 (15:33 +0200)
committerStas Vilchik <vilchiks@gmail.com>
Wed, 15 Oct 2014 13:33:35 +0000 (15:33 +0200)
server/sonar-web/src/main/webapp/WEB-INF/app/views/measures/search.html.erb

index 397b575f01d21164ec40423338cf6c5750c32a84..168c56d5b9e0e5e439068053761fc53b2fb008c8 100644 (file)
 
 
   var queryParams = [
-    { key: 'qualifiers[]', value: <%= @filter.criteria['qualifiers'].to_json -%> },
-    { key: 'alertLevels[]', value: <%= @filter.criteria['alertLevels'].to_json -%> },
+    { key: 'qualifiers[]', value: <%= json_escape(@filter.criteria['qualifiers'].to_json) -%> },
+    { key: 'alertLevels[]', value: <%= json_escape(@filter.criteria['alertLevels'].to_json) -%> },
     { key: 'fromDate', value: '<%= h @filter.criteria['fromDate'] -%>' },
     { key: 'toDate', value: '<%= h @filter.criteria['toDate'] -%>' },
     { key: 'ageMinDays', value: '<%= h @filter.criteria('ageMinDays') -%>' },