From cf09b99aea0012fd3b883cc12c54d30a05cb1b1c Mon Sep 17 00:00:00 2001 From: Michael Herger Date: Tue, 14 Nov 2017 22:29:24 +0100 Subject: [PATCH] Fixes Issue #175 Encode HTML entities to prevent some XSS exploits. --- HTML/EN/html/errors/403.html | 2 +- HTML/EN/html/errors/404.html | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/HTML/EN/html/errors/403.html b/HTML/EN/html/errors/403.html index 0dcedb60b31..400c2ad21c8 100644 --- a/HTML/EN/html/errors/403.html +++ b/HTML/EN/html/errors/403.html @@ -1,4 +1,4 @@ 403 Forbidden -403 Forbidden: [% path %] +403 Forbidden: [% path | html_entity %] [% validURL %] diff --git a/HTML/EN/html/errors/404.html b/HTML/EN/html/errors/404.html index fc1fc575468..2ba56490376 100644 --- a/HTML/EN/html/errors/404.html +++ b/HTML/EN/html/errors/404.html @@ -1,4 +1,4 @@ 404 Not Found -404 Not Found: [% path %] +404 Not Found: [% path | html_entity %] [% IF suggestion %]

[% suggestion | html %]

[% END %]