luci-app-openvpn: fix potential XSS in pageswitch template
Ensure to escape URL instance parameter displayed in the heading. Signed-off-by: Jo-Philipp Wich <jo@mein.io> (cherry picked from commit 25983b9fa572a640a7ecd077378df2790266cd61)
This commit is contained in:
parent
aa7938d4cb
commit
749268a2ca
@ -9,7 +9,7 @@
|
||||
<div class="cbi-section">
|
||||
<h3>
|
||||
<a href="<%=url('admin/vpn/openvpn')%>"><%:Overview%></a> »
|
||||
<%=luci.i18n.translatef("Instance \"%s\"", self.instance)%>
|
||||
<%=luci.i18n.translatef("Instance \"%s\"", pcdata(self.instance))%>
|
||||
</h3>
|
||||
<% if self.mode == "basic" then %>
|
||||
<a href="<%=url('admin/vpn/openvpn/advanced', self.instance)%>"><%:Switch to advanced configuration%> »</a><p/>
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user