Skip to content

Commit 22bc5d5

Browse files
author
patched.codes[bot]
committed
Patched src/com/ibm/security/appscan/altoromutual/servlet/AdminServlet.java
1 parent 1d0851d commit 22bc5d5

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

src/com/ibm/security/appscan/altoromutual/servlet/AdminServlet.java

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,7 @@
2525
import javax.servlet.http.HttpServletResponse;
2626

2727
import com.ibm.security.appscan.altoromutual.util.DBUtil;
28+
import org.apache.commons.text.StringEscapeUtils;
2829

2930
/**
3031
* This servlet handles site admin operations
@@ -115,7 +116,8 @@ else if (request.getRequestURL().toString().endsWith("changePassword")){
115116
else
116117
message = "Requested operation has completed successfully.";
117118

118-
request.getSession().setAttribute("message", message);
119+
String safeMessage = StringEscapeUtils.escapeHtml4(message);
120+
request.getSession().setAttribute("message", safeMessage);
119121
response.sendRedirect("admin.jsp");
120122
return ;
121123
}

0 commit comments

Comments
 (0)