fix: missing escape on ACP category backgroundImage property

This commit is contained in:
Julian Lam
2022-09-02 12:30:55 -04:00
parent 61d1e9e0d4
commit 67cb70352f

View File

@@ -86,7 +86,7 @@ function modifyCategory(category, fields) {
db.parseIntFields(category, intFields, fields);
const escapeFields = ['name', 'color', 'bgColor', 'imageClass', 'class', 'link'];
const escapeFields = ['name', 'color', 'bgColor', 'backgroundImage', 'imageClass', 'class', 'link'];
escapeFields.forEach((field) => {
if (category.hasOwnProperty(field)) {
category[field] = validator.escape(String(category[field] || ''));