mirror of
https://github.com/NodeBB/NodeBB.git
synced 2026-06-26 13:10:22 +02:00
backport xss fix
This commit is contained in:
committed by
GitHub
parent
c3b6974779
commit
1fefc8d427
@@ -1,6 +1,7 @@
|
||||
"use strict";
|
||||
|
||||
var async = require('async');
|
||||
var validator = require('validator');
|
||||
var posts = require('../../posts');
|
||||
var analytics = require('../../analytics');
|
||||
|
||||
@@ -36,7 +37,7 @@ flagsController.get = function(req, res, next) {
|
||||
posts: results.posts,
|
||||
analytics: results.analytics,
|
||||
next: stop + 1,
|
||||
byUsername: byUsername,
|
||||
byUsername: validator.escape(String(byUsername)),
|
||||
title: '[[pages:flagged-posts]]'
|
||||
};
|
||||
res.render('admin/manage/flags', data);
|
||||
|
||||
Reference in New Issue
Block a user