From b663a2fb90ff5e478fc0f56e03c2f134ea1502e4 Mon Sep 17 00:00:00 2001 From: jvoisin Date: Sun, 28 Apr 2019 08:49:25 +0000 Subject: [PATCH] Fix a stored XSS --- .../src/main/webapp/WEB-INF/jsp/transcodingSettings.jsp | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/airsonic-main/src/main/webapp/WEB-INF/jsp/transcodingSettings.jsp b/airsonic-main/src/main/webapp/WEB-INF/jsp/transcodingSettings.jsp index 3d470f17..925939b7 100644 --- a/airsonic-main/src/main/webapp/WEB-INF/jsp/transcodingSettings.jsp +++ b/airsonic-main/src/main/webapp/WEB-INF/jsp/transcodingSettings.jsp @@ -27,7 +27,7 @@ - + @@ -41,7 +41,7 @@ - " value="${newTranscoding.name}"/> + " value="${fn:escapeXml(newTranscoding.name)}"/> " value="${newTranscoding.sourceFormats}"/> " value="${newTranscoding.targetFormat}"/> " value="${newTranscoding.step1}"/>