Fix #3139: XSS in Related Tags javascript.
This commit is contained in:
@@ -227,14 +227,10 @@
|
|||||||
if (text.match(/^ http/)) {
|
if (text.match(/^ http/)) {
|
||||||
text = text.substring(1, 1000);
|
text = text.substring(1, 1000);
|
||||||
var $url = $("<a/>");
|
var $url = $("<a/>");
|
||||||
$url.text("open");
|
$url.text(text);
|
||||||
$url.attr("href", text);
|
$url.attr("href", text);
|
||||||
$url.attr("target", "_blank");
|
$url.attr("target", "_blank");
|
||||||
var $li = $("<li/>");
|
$ul.append($("<li/>").html($url));
|
||||||
$li.append(text + " [");
|
|
||||||
$li.append($url);
|
|
||||||
$li.append("]");
|
|
||||||
$ul.append($li);
|
|
||||||
} else {
|
} else {
|
||||||
$ul.append($("<li/>").text(text));
|
$ul.append($("<li/>").text(text));
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user