Skip to content

Commit 3daddcf

Browse files
authored
Close XSS in node image manager
1 parent 50d9192 commit 3daddcf

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

app/Http/Controllers/Maps/CustomMapNodeImageController.php

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -87,7 +87,7 @@ public function store(FormRequest $request): JsonResponse
8787
return response()->json([
8888
'result' => 'success',
8989
'id' => $image->custom_map_node_image_id,
90-
'name' => $image->name,
90+
'name' => htmlentities($image->name),
9191
'version' => $image->version,
9292
]);
9393
}
@@ -105,7 +105,7 @@ public function update(FormRequest $request, CustomMapNodeImage $image): JsonRes
105105

106106
return response()->json([
107107
'result' => 'success',
108-
'name' => $request['name'],
108+
'name' => htmlentities($image->name),
109109
'version' => $image->version,
110110
]);
111111
}

0 commit comments

Comments
 (0)