From 71c919f4eb131ec8d581f399a58662cbf3a9b4a6 Mon Sep 17 00:00:00 2001 From: nerrorsec <42860825+nerrorsec@users.noreply.github.com> Date: Mon, 25 Apr 2022 11:20:44 +0545 Subject: [PATCH] Fixes stored xss via Scan Engine Name --- web/static/custom/right_sidebar.js | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/web/static/custom/right_sidebar.js b/web/static/custom/right_sidebar.js index 4f18665c6..582c89a79 100644 --- a/web/static/custom/right_sidebar.js +++ b/web/static/custom/right_sidebar.js @@ -18,7 +18,7 @@ function getScanStatusSidebar(reload) { for (var scan in scans['pending']) { scan_object = scans['pending'][scan]; $('#upcoming_scans').append(` - + `); } } @@ -35,7 +35,7 @@ function getScanStatusSidebar(reload) {
- ${scan_object.scan_type.engine_name} on ${scan_object.domain.name} + ${htmlEncode(scan_object.scan_type.engine_name)} on ${scan_object.domain.name} ${scan_object.current_progress}% @@ -91,7 +91,7 @@ function getScanStatusSidebar(reload) {