修复访问日志XSS漏洞

This commit is contained in:
刘祥超
2022-02-23 17:34:54 +08:00
parent 5fe1384e55
commit 619934a275
3 changed files with 12 additions and 10 deletions

View File

@@ -624,10 +624,10 @@ window.teaweb = {
return instance
},
encodeHTML: function (s) {
s = s.replace("&", "&")
s = s.replace("<", "&lt;")
s = s.replace(">", "&gt;")
s = s.replace("\"", "&quot;")
s = s.replace(/&/g, "&amp;")
s = s.replace(/</g, "&lt;")
s = s.replace(/>/g, "&gt;")
s = s.replace(/"/, "&quot;")
return s
}
}