Skip to content

Commit 29d3a0e

Browse files
committed
Escape the user controlled error parameter
1 parent 2835e38 commit 29d3a0e

File tree

1 file changed

+1
-1
lines changed
  • deps/rabbitmq_management/priv/www/js

1 file changed

+1
-1
lines changed

deps/rabbitmq_management/priv/www/js/main.js

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ $(document).ready(function() {
44
var url = new URL(url_string);
55
var error = url.searchParams.get("error");
66
if (error) {
7-
renderWarningMessageInLoginStatus(error);
7+
renderWarningMessageInLoginStatus(fmt_escape_html(error));
88
}else {
99
if (oauth.enabled) {
1010
if (!oauth.logged_in ) {

0 commit comments

Comments
 (0)