1
0
mirror of https://github.com/d47081/qBittorrent.git synced 2025-01-11 07:18:08 +00:00

Fix encoding of special characters

Special characters would get html encoded (& -> &amp;). This has been tested against several payloads (e.g. <script>alert(0)</script>) to ensure it's not vulnerable to XSS.
This commit is contained in:
Tom Piccirello 2019-06-20 22:15:32 -07:00 committed by GitHub
parent 183db3475a
commit 368fbd9e7d
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -33,7 +33,7 @@
var name = new URI().getData('name');
// set text field to current value
if (name)
$('rename').value = escapeHtml(decodeURIComponent(name));
$('rename').value = decodeURIComponent(name);
$('rename').focus();
$('renameButton').addEvent('click', function(e) {