luci-app-openvpn: fix potential XSS in pageswitch template
Ensure to escape URL instance parameter displayed in the heading. Signed-off-by: Jo-Philipp Wich <jo@mein.io>
This commit is contained in:
parent
0186d7eae0
commit
25983b9fa5
1 changed files with 1 additions and 1 deletions
|
@ -9,7 +9,7 @@
|
|||
<div class="cbi-section">
|
||||
<h3>
|
||||
<a href="<%=url('admin/vpn/openvpn')%>"><%:Overview%></a> »
|
||||
<%=luci.i18n.translatef("Instance \"%s\"", self.instance)%>
|
||||
<%=luci.i18n.translatef("Instance \"%s\"", pcdata(self.instance))%>
|
||||
</h3>
|
||||
<% if self.mode == "basic" then %>
|
||||
<a href="<%=url('admin/vpn/openvpn/advanced', self.instance)%>"><%:Switch to advanced configuration%> »</a><p/>
|
||||
|
|
Loading…
Reference in a new issue