Skip to content

Commit

Permalink
fix: added missing escaping of newly added values
Browse files Browse the repository at this point in the history
  • Loading branch information
thorsten committed Jan 25, 2023
1 parent d896456 commit 26663ef
Showing 1 changed file with 6 additions and 2 deletions.
8 changes: 6 additions & 2 deletions phpmyfaq/admin/instances.php
Expand Up @@ -243,6 +243,10 @@ class="btn btn-danger pmf-instance-delete"
const admin = $('#admin').val();
const password = $('#password').val();

const escape = (unsafe) => {
return unsafe.replaceAll('&', '&amp;').replaceAll('<', '&lt;').replaceAll('>', '&gt;').replaceAll('"', '&quot;').replaceAll("'", '&#039;');
}

$.ajax({
url: 'index.php',
type: 'GET',
Expand All @@ -256,8 +260,8 @@ class="btn btn-danger pmf-instance-delete"
'<tr id="row-instance-' + data.added + '">' +
'<td>' + data.added + '</td>' +
'<td><a href="' + data.url + '">' + data.url + '</a></td>' +
'<td>' + instance + '</td>' +
'<td>' + comment + '</td>' +
'<td>' + escape(instance) + '</td>' +
'<td>' + escape(comment) + '</td>' +
'<td>' +
'<a href="?action=editinstance&instance_id=' + data.added +
'" class="btn btn-info"><i aria-hidden="true" class="fa fa-pencil"></i></a>' +
Expand Down

0 comments on commit 26663ef

Please sign in to comment.