mirror of
https://github.com/NodeBB/NodeBB.git
synced 2025-12-26 18:30:20 +01:00
escape error message on 500 page
This commit is contained in:
@@ -6,6 +6,7 @@ var nconf = require('nconf'),
|
||||
controllers = require('../controllers'),
|
||||
plugins = require('../plugins'),
|
||||
express = require('express'),
|
||||
validator = require('validator'),
|
||||
|
||||
accountRoutes = require('./accounts'),
|
||||
|
||||
@@ -195,7 +196,7 @@ function handleErrors(app, middleware) {
|
||||
res.json({path: req.path, error: err.message});
|
||||
} else {
|
||||
middleware.buildHeader(req, res, function() {
|
||||
res.render('500', {path: req.path, error: err.message});
|
||||
res.render('500', {path: req.path, error: validator.escape(err.message)});
|
||||
});
|
||||
}
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user