diff options
author | Bjoern Schiessle <schiessle@owncloud.com> | 2012-06-18 09:42:31 +0200 |
---|---|---|
committer | Bjoern Schiessle <schiessle@owncloud.com> | 2012-06-18 09:42:31 +0200 |
commit | 91f69858e49c3981d31eeee428c7bf3cd5e142fe (patch) | |
tree | d914789e5962407a7868ff29b46110604f8e6181 /settings | |
parent | e5feb4e1aab49fe658f65e9503b268eb3f41882d (diff) | |
download | nextcloud-server-91f69858e49c3981d31eeee428c7bf3cd5e142fe.tar.gz nextcloud-server-91f69858e49c3981d31eeee428c7bf3cd5e142fe.zip |
escape log messages to avoid possible js execution
Diffstat (limited to 'settings')
-rw-r--r-- | settings/js/log.js | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/settings/js/log.js b/settings/js/log.js index 6063c7d9a9f..bde8b8b104c 100644 --- a/settings/js/log.js +++ b/settings/js/log.js @@ -39,7 +39,7 @@ OC.Log={ row.append(appTd); var messageTd=$('<td/>'); - messageTd.text(entry.message); + messageTd.text(entry.message.replace(/</, "<").replace(/>/, ">")); row.append(messageTd); var timeTd=$('<td/>'); |