mirror of
https://github.com/Icinga/icingaweb2.git
synced 2025-07-23 13:54:26 +02:00
Dashboard settings: escape panes' names to prevent XSS
This commit is contained in:
parent
358b20cec3
commit
b670855f25
@ -20,7 +20,7 @@
|
||||
<?php foreach ($this->dashboard->getPanes() as $pane): ?>
|
||||
<tr style="background-color: #f1f1f1;">
|
||||
<th colspan="2" style="text-align: left; padding: 0.5em;">
|
||||
<?= $pane->getName(); ?>
|
||||
<?= $this->escape($pane->getName()) ?>
|
||||
</th>
|
||||
<th>
|
||||
<?= $this->qlink(
|
||||
|
Loading…
x
Reference in New Issue
Block a user