Skip to content

Commit 862ca21

Browse files
authored
Merge pull request #16611 from nextcloud/backport/16599/stable15
[stable15] Fix/xss/on favorite file
2 parents 792d8fb + cadd6fa commit 862ca21

File tree

2 files changed

+2
-2
lines changed

2 files changed

+2
-2
lines changed

apps/files/js/tagsplugin.js

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -103,7 +103,7 @@
103103
var innerTagA = document.createElement('A');
104104
innerTagA.setAttribute("href", url);
105105
innerTagA.setAttribute("class", "nav-icon-files svg");
106-
innerTagA.innerHTML = appName;
106+
innerTagA.innerHTML = _.escape(appName);
107107

108108
var length = listLIElements.length + 1;
109109
var innerTagLI = document.createElement('li');

apps/theming/js/3rdparty/jscolor/jscolor.js

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1100,7 +1100,7 @@ var jsc = {
11001100
if (jsc.isElementType(this.valueElement, 'input')) {
11011101
this.valueElement.value = value;
11021102
} else {
1103-
this.valueElement.innerHTML = value;
1103+
this.valueElement.innerHTML = _.escape(value);
11041104
}
11051105
}
11061106
if (!(flags & jsc.leaveStyle)) {

0 commit comments

Comments
 (0)