From f05ac47eb65c1bb418d89636c660093c79e4bef5 Mon Sep 17 00:00:00 2001 From: Olivier Paroz Date: Fri, 29 May 2015 18:34:38 +0200 Subject: Escape single quotes --- core/js/oc-dialogs.js | 2 ++ 1 file changed, 2 insertions(+) (limited to 'core/js/oc-dialogs.js') diff --git a/core/js/oc-dialogs.js b/core/js/oc-dialogs.js index 8ebce841bea..9f88c268369 100644 --- a/core/js/oc-dialogs.js +++ b/core/js/oc-dialogs.js @@ -389,6 +389,8 @@ var OCdialogs = { forceIcon: 0 }; var previewpath = OC.generateUrl('/core/preview.png?') + $.param(urlSpec); + // Escaping single quotes + previewpath = previewpath.replace(/'/g, "%27") $originalDiv.find('.icon').css({"background-image": "url('" + previewpath + "')"}); getCroppedPreview(replacement).then( function(path){ -- cgit v1.2.3