mirror of
https://github.com/FortAwesome/Font-Awesome.git
synced 2024-12-26 13:31:30 +08:00
Fix script injection by using _.template escaping
This commit is contained in:
parent
3fbc684636
commit
75cdda9bf7
@ -57,7 +57,7 @@ relative_path: ../
|
||||
{% include icons/medical.html %}
|
||||
</div>
|
||||
<script type="text/template" id="results-template">
|
||||
<h2 class="page-header">Search for '<span class="text-color-default"><%= content.query %></span>'</h2>
|
||||
<h2 class="page-header">Search for '<span class="text-color-default"><%- content.query %></span>'</h2>
|
||||
<% if (content.nbHits > 0) { %>
|
||||
<div class="row fontawesome-icon-list">
|
||||
<%= results %>
|
||||
|
Loading…
Reference in New Issue
Block a user