mirror of
https://github.com/Azure/cosmos-explorer.git
synced 2026-06-08 13:37:29 +01:00
Fix stored XSS via Cassandra column names in DataTable headers (#2499)
Co-authored-by: Asier Isayas <aisayas@microsoft.com>
This commit is contained in:
@@ -93,7 +93,7 @@ function createDataTable(
|
|||||||
|
|
||||||
for (var i = 0; i < tableEntityListViewModel.headers.length; i++) {
|
for (var i = 0; i < tableEntityListViewModel.headers.length; i++) {
|
||||||
jsonColTable.push({
|
jsonColTable.push({
|
||||||
sTitle: tableEntityListViewModel.headers[i],
|
sTitle: Utilities.htmlEncode(tableEntityListViewModel.headers[i]),
|
||||||
data: tableEntityListViewModel.headers[i],
|
data: tableEntityListViewModel.headers[i],
|
||||||
aTargets: [i],
|
aTargets: [i],
|
||||||
mRender: bindColumn,
|
mRender: bindColumn,
|
||||||
|
|||||||
Reference in New Issue
Block a user