Fixed an XSS discovered by Mario in the default keylogger.
This commit is contained in:
@@ -45,7 +45,7 @@ DataGrid = function(url, page, base) {
|
|||||||
dataIndex: 'type',
|
dataIndex: 'type',
|
||||||
sortable: true,
|
sortable: true,
|
||||||
width: 60,
|
width: 60,
|
||||||
renderer: function(value, metaData, record, rowIndex, colIndex, store) {
|
renderer: function(value) {
|
||||||
return "<b>" + $jEncoder.encoder.encodeForHTML(value) + "</b>";
|
return "<b>" + $jEncoder.encoder.encodeForHTML(value) + "</b>";
|
||||||
}
|
}
|
||||||
}, {
|
}, {
|
||||||
@@ -54,7 +54,9 @@ DataGrid = function(url, page, base) {
|
|||||||
dataIndex: 'event',
|
dataIndex: 'event',
|
||||||
sortable:true,
|
sortable:true,
|
||||||
width: 420,
|
width: 420,
|
||||||
renderer: $jEncoder.encoder.encodeForHTML(this.formatTitle)
|
renderer: function(value){
|
||||||
|
return $jEncoder.encoder.encodeForHTML(value);
|
||||||
|
}
|
||||||
}, {
|
}, {
|
||||||
id: 'log-date',
|
id: 'log-date',
|
||||||
header: "Date",
|
header: "Date",
|
||||||
|
|||||||
Reference in New Issue
Block a user