fix xss / GH-2252

ref https://github.com/serghey-rodin/vesta/issues/2252
This commit is contained in:
divinity76 2022-07-23 09:26:16 +02:00 committed by GitHub
commit 0682f7b10c
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -1191,6 +1191,13 @@ class UploadHandler
));
}
}
if(!headers_sent()){
// this is the most likely/expected path.
header("Content-Type: text/javascript; charset=UTF-8");
} else {
// html-encode json to prevent xss...
$json = htmlentities($json, ENT_QUOTES | ENT_SUBSTITUTE | ENT_DISALLOWED | ENT_HTML401);
}
$this->body($json);
}
return $content;