diff options
author | Matthew Somerville <matthew-github@dracos.co.uk> | 2016-07-06 12:16:33 +0100 |
---|---|---|
committer | Matthew Somerville <matthew-github@dracos.co.uk> | 2016-07-06 16:24:18 +0100 |
commit | e57204c2676664a2d6551a7f2c859d722646b28c (patch) | |
tree | 4807bb18ff1fdf924e7e8f3d0240e05a701fec50 /bin/site-specific-install.sh | |
parent | 738b56a6b7d0a8ca93f78406054a7c9edae85fc3 (diff) |
Fix two XSS vulnerabilities.
The title in the OpenGraph header was not being properly escaped, and
the hide pins/all pins links were using single quotes which were able
to be broken out of.
Also remove the single quotes around rss_feed_uri, though this is not
a vulnerability as its contents were sanitised (postcode or co-ords).
Diffstat (limited to 'bin/site-specific-install.sh')
0 files changed, 0 insertions, 0 deletions