fix: xss on flags page via ban reason

This commit is contained in:
Barış Soner Uşaklı
2021-09-17 11:10:43 -04:00
parent 66eaae44a6
commit ba3582b873

View File

@@ -794,7 +794,7 @@ async function mergeBanHistory(history, targetUid, uids) {
meta: [ meta: [
{ {
key: '[[user:banned]]', key: '[[user:banned]]',
value: cur.reason, value: validator.escape(String(cur.reason)),
labelClass: 'danger', labelClass: 'danger',
}, },
{ {