From: Lukas Reschke Date: Sun, 3 Mar 2013 23:54:21 +0000 (+0100) Subject: Sanitize shareWith X-Git-Tag: v5.0.0RC2~24^2 X-Git-Url: https://source.dussan.org/?a=commitdiff_plain;h=577945bd338e3f9b1f30aa026c84247f2720ecb6;p=nextcloud-server.git Sanitize shareWith --- diff --git a/core/js/share.js b/core/js/share.js index 145c31a86c8..34f24da4df7 100644 --- a/core/js/share.js +++ b/core/js/share.js @@ -309,12 +309,12 @@ OC.Share={ if (permissions & OC.PERMISSION_SHARE) { shareChecked = 'checked="checked"'; } - var html = '
  • '; + var html = '
  • '; html += ''; if(shareWith.length > 14){ - html += shareWithDisplayName.substr(0,11) + '...'; + html += escapeHTML(shareWithDisplayName.substr(0,11) + '...'); }else{ - html += shareWithDisplayName; + html += escapeHTML(shareWithDisplayName); } if (possiblePermissions & OC.PERMISSION_CREATE || possiblePermissions & OC.PERMISSION_UPDATE || possiblePermissions & OC.PERMISSION_DELETE) { if (editChecked == '') {