Browse Source

Fixed XSS in 'Text Encoding Brute Force. Closes #539

n1474335 6 years ago
parent
commit
01f0625d6a
1 changed files with 1 additions and 1 deletions
  1. 1 1
      src/core/operations/TextEncodingBruteForce.mjs

+ 1 - 1
src/core/operations/TextEncodingBruteForce.mjs

@@ -79,7 +79,7 @@ class TextEncodingBruteForce extends Operation {
         let table = "<table class='table table-hover table-sm table-bordered table-nonfluid'><tr><th>Encoding</th><th>Value</th></tr>";
 
         for (const enc in encodings) {
-            const value = Utils.printable(encodings[enc], true);
+            const value = Utils.escapeHtml(Utils.printable(encodings[enc], true));
             table += `<tr><td>${enc}</td><td>${value}</td></tr>`;
         }