From 6418caf700bd1f62a236f90541891e8bfed030ea Mon Sep 17 00:00:00 2001 From: Joffrey JAFFEUX Date: Mon, 21 Jan 2019 13:08:26 +0100 Subject: [PATCH] SECURITY: fix possible XSS with badges (#6912) --- app/assets/javascripts/admin/templates/user-badges.hbs | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/assets/javascripts/admin/templates/user-badges.hbs b/app/assets/javascripts/admin/templates/user-badges.hbs index 52faf9b4333..da64e5d3b99 100644 --- a/app/assets/javascripts/admin/templates/user-badges.hbs +++ b/app/assets/javascripts/admin/templates/user-badges.hbs @@ -16,7 +16,7 @@
- {{combo-box filterable=true value=selectedBadgeId content=grantableBadges}} + {{combo-box forceEscape=true filterable=true value=selectedBadgeId content=grantableBadges}}