Skip to content

Commit 35f8190

Browse files
authored
RA-1424: escapeJs vulnerable to XSS (#92)
1 parent 2e5939d commit 35f8190

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

omod/src/main/webapp/pages/userApp.gsp

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -43,7 +43,7 @@
4343
${ui.message("referenceapplication.app.appId.label")} (${ ui.message("coreapps.formValidation.messages.requiredField.label") })
4444
</span>
4545
</label>
46-
<input class="form-control form-control-sm form-control-lg form-control-md required" id="appId-field" type="text" name="appId" value="${userApp.appId ? ui.escapeJs(ui.escapeHtml(userApp.appId)) : ""}" size="80" placeholder="${ ui.message("referenceapplication.app.definition.placeholder") }" />
46+
<input class="form-control form-control-sm form-control-lg form-control-md required" id="appId-field" type="text" name="appId" value="${userApp.appId ? ui.encodeJavaScript(ui.escapeHtml(userApp.appId)) : ""}" size="80" placeholder="${ ui.message("referenceapplication.app.definition.placeholder") }" />
4747
<%}%>
4848
</p>
4949
<p>

0 commit comments

Comments
 (0)