Skip to content

Commit

Permalink
Fix XSS in Statistics
Browse files Browse the repository at this point in the history
  • Loading branch information
eljeffeg committed May 3, 2022
1 parent fd5423f commit f13f0a6
Show file tree
Hide file tree
Showing 2 changed files with 5 additions and 5 deletions.
2 changes: 1 addition & 1 deletion setup/__init__.py
Original file line number Diff line number Diff line change
@@ -1,2 +1,2 @@
# -*- coding: utf-8 -*-
__version__ = "3.10.4"
__version__ = "3.10.5"
8 changes: 4 additions & 4 deletions static/js/pages/admin/view/statistics.js
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ function getStatDetails(obj, uuid) {
$("#flag_value").text(value[0]["price"]);
$("#details_flag_name").text(value[0].name);
$("#details_flag_description").text(value[0].description);
$("#details_flag_token").text(value[0].token);
$("#details_flag_token").text(htmlEncode(value[0].token));
$("#count_attempts").text(response["attempts"].length);
$("#count_captures").text(response["captures"].length);
$("#count_hints").text(response["hints"].length);
Expand All @@ -18,10 +18,10 @@ function getStatDetails(obj, uuid) {
var table = "";
if (value.length > 0) {
for (i=0; i < value.length; i++) {
let tkn = $('<div>').html(value[i].token);
let nm = $('<div>').html(value[i].name);
let tkn = $('<div>').text(htmlEncode(value[i].token));
let nm = $('<div>').text(value[i].name);
table += "<tr><td class='shortcolumn statcolumn'>" + nm.text() + "</td>";
if (value[i].token !== undefined) {
if (htmlEncode(value[i].token) !== undefined) {
table += "<td class='descriptioncol' style='text-align: center;'>" + tkn.text() + "</td>";
}
if (value[i].price !== undefined) {
Expand Down

0 comments on commit f13f0a6

Please sign in to comment.