summaryrefslogtreecommitdiffstats
path: root/apps/files_versions/js
diff options
context:
space:
mode:
authorLukas Reschke <lukas@statuscode.ch>2012-10-12 14:08:06 +0200
committerLukas Reschke <lukas@statuscode.ch>2012-10-12 14:09:58 +0200
commite45f36c2d4161f59f9a87cc9b9c884e4600f42a8 (patch)
treed0823a586928aba246d7ca6d032336aecda2ef34 /apps/files_versions/js
parentd7f43945e793bb9ec09ab7c40cc566e0221cf995 (diff)
downloadnextcloud-server-e45f36c2d4161f59f9a87cc9b9c884e4600f42a8.tar.gz
nextcloud-server-e45f36c2d4161f59f9a87cc9b9c884e4600f42a8.zip
Sanitize user input
Diffstat (limited to 'apps/files_versions/js')
-rw-r--r--apps/files_versions/js/versions.js2
1 files changed, 1 insertions, 1 deletions
diff --git a/apps/files_versions/js/versions.js b/apps/files_versions/js/versions.js
index 87396cd0ba1..07c5655560e 100644
--- a/apps/files_versions/js/versions.js
+++ b/apps/files_versions/js/versions.js
@@ -45,7 +45,7 @@ function createVersionsDropdown(filename, files) {
var historyUrl = OC.linkTo('files_versions', 'history.php') + '?path='+encodeURIComponent( $( '#dir' ).val() ).replace( /%2F/g, '/' )+'/'+encodeURIComponent( filename );
- var html = '<div id="dropdown" class="drop drop-versions" data-file="'+files+'">';
+ var html = '<div id="dropdown" class="drop drop-versions" data-file="'+escapeHTML(files)+'">';
html += '<div id="private">';
html += '<select data-placeholder="Saved versions" id="found_versions" class="chzen-select" style="width:16em;">';
html += '<option value=""></option>';