Skip to content

Commit

Permalink
Merge pull request #618 from nerrorsec/patch-1
Browse files Browse the repository at this point in the history
Fixes stored xss via Scan Engine Name
  • Loading branch information
yogeshojha committed Apr 25, 2022
2 parents 8f8cc0d + 71c919f commit 0397b3f
Showing 1 changed file with 5 additions and 5 deletions.
10 changes: 5 additions & 5 deletions web/static/custom/right_sidebar.js
Expand Up @@ -18,7 +18,7 @@ function getScanStatusSidebar(reload) {
for (var scan in scans['pending']) {
scan_object = scans['pending'][scan];
$('#upcoming_scans').append(`
<div class="alert alert-warning" role="alert">${scan_object.scan_type.engine_name} on ${scan_object.domain.name}</div>
<div class="alert alert-warning" role="alert">${htmlEncode(scan_object.scan_type.engine_name)} on ${scan_object.domain.name}</div>
`);
}
}
Expand All @@ -35,7 +35,7 @@ function getScanStatusSidebar(reload) {
<div class="card border-primary border mini-card">
<a href="/scan/detail/${scan_object.id}" class="text-reset item-hovered">
<div class="card-header bg-soft-primary text-primary mini-card-header">
${scan_object.scan_type.engine_name} on ${scan_object.domain.name}
${htmlEncode(scan_object.scan_type.engine_name)} on ${scan_object.domain.name}
<span class="badge badge-soft-primary float-end">
${scan_object.current_progress}%
</span>
Expand Down Expand Up @@ -91,7 +91,7 @@ function getScanStatusSidebar(reload) {
<div class="card border-${color} border mini-card">
<a href="/scan/detail/${scan_object.id}" class="text-reset item-hovered float-end">
<div class="card-header ${bg_color} text-${color} mini-card-header">
${scan_object.scan_type.engine_name} on ${scan_object.domain.name}
${htmlEncode(scan_object.scan_type.engine_name)} on ${scan_object.domain.name}
</div>
<div class="card-body mini-card-body">
<p class="card-text">
Expand Down Expand Up @@ -130,7 +130,7 @@ function getScanStatusSidebar(reload) {
<div class="card border-primary border mini-card">
<a href="#" onclick="show_subscan_results(${task_object['id']})" class="text-reset item-hovered">
<div class="card-header bg-soft-primary text-primary mini-card-header">
${task_name} on <b>${task_object.subdomain_name}</b> using engine <b>${task_object.engine}</b>
${task_name} on <b>${task_object.subdomain_name}</b> using engine <b>${htmlEncode(task_object.engine)}</b>
</div>
<div class="card-body mini-card-body">
<p class="card-text">
Expand Down Expand Up @@ -181,7 +181,7 @@ function getScanStatusSidebar(reload) {
<div class="card border-${color} border mini-card">
<a href="#" class="text-reset item-hovered" onclick="show_subscan_results(${task_object['id']})">
<div class="card-header ${bg_color} text-${color} mini-card-header">
${task_name} on <b>${task_object.subdomain_name}</b> using engine <b>${task_object.engine}</b>
${task_name} on <b>${task_object.subdomain_name}</b> using engine <b>${htmlEncode(task_object.engine)}</b>
</div>
<div class="card-body mini-card-body">
<p class="card-text">
Expand Down

0 comments on commit 0397b3f

Please sign in to comment.