Browse Source

Fix unsanitised text vulnerability in post/fileinfo.html

pull/40/head
Michael Walker 10 years ago
parent
commit
8aff83bdd4
  1. 2
      templates/post/fileinfo.html

2
templates/post/fileinfo.html

@ -22,7 +22,7 @@
{% if config.show_filename and file.filename %}
,
{% if file.filename|length > config.max_filename_display %}
<span class="postfilename" title="{{ file.filename|e }}">{{ file.filename|truncate_filename(config.max_filename_display)|bidi_cleanup }}</span>
<span class="postfilename" title="{{ file.filename|e|bidi_cleanup }}">{{ file.filename|truncate_filename(config.max_filename_display)|bidi_cleanup }}</span>
{% else %}
<span class="postfilename">{{ file.filename|e|bidi_cleanup }}</span>
{% endif %}

Loading…
Cancel
Save