Merge pull request #10259 from FortAwesome/search-script-injection

Fix script injection by using _.template escaping
This commit is contained in:
Dave Gandy 2016-11-21 11:37:31 -05:00 committed by GitHub
commit 49100c7c3a

View File

@ -57,7 +57,7 @@ relative_path: ../
{% include icons/medical.html %} {% include icons/medical.html %}
</div> </div>
<script type="text/template" id="results-template"> <script type="text/template" id="results-template">
<h2 class="page-header">Search for '<span class="text-color-default"><%= content.query %></span>'</h2> <h2 class="page-header">Search for '<span class="text-color-default"><%- content.query %></span>'</h2>
<% if (content.nbHits > 0) { %> <% if (content.nbHits > 0) { %>
<div class="row fontawesome-icon-list"> <div class="row fontawesome-icon-list">
<%= results %> <%= results %>