Subject: [PATCH] Fix an XSS vulnerability

POC:
```
http://192.168.100.1/cgi-bin/luci//"><iframe src="javascript:alert(test)
```

fix https://github.com/jerrykuku/luci-theme-argon/issues/563

Signed-off-by: jjm2473 <jjm2473@gmail.com>
Signed-off-by: sbwml <admin@cooluc.com>
This commit is contained in:
jjm2473 2025-03-25 20:16:55 +08:00 committed by sbwml
parent 9a4cc4f94c
commit ade243f27f

View File

@ -151,7 +151,7 @@
<body
class="lang_<%=luci.i18n.context.lang%> <% if node then %><%= striptags( node.title ) %><% end %> <% if luci.dispatcher.context.authsession then %>logged-in<% end %>"
data-page="<%= table.concat(disp.context.requestpath, "-") %>">
data-page="<%= pcdata(table.concat(disp.context.requestpath, "-")) %>">
<div class="main">
<div class="main-left" id="mainmenu" style="display:none">