Fix stored XSS via Cassandra column names in DataTable headers (#2499)

Co-authored-by: Asier Isayas <aisayas@microsoft.com>
This commit is contained in:
asier-isayas
2026-05-26 16:44:10 -04:00
committed by GitHub
parent 5ee2ca37d5
commit 41ae13ea3a
@@ -93,7 +93,7 @@ function createDataTable(
for (var i = 0; i < tableEntityListViewModel.headers.length; i++) {
jsonColTable.push({
sTitle: tableEntityListViewModel.headers[i],
sTitle: Utilities.htmlEncode(tableEntityListViewModel.headers[i]),
data: tableEntityListViewModel.headers[i],
aTargets: [i],
mRender: bindColumn,