mirror of
https://github.com/Combodo/iTop.git
synced 2026-05-19 07:12:26 +02:00
N°6483 - Security hardening
This commit is contained in:
@@ -872,13 +872,13 @@ $(function()
|
|||||||
// - Make a jQuery element for a list item
|
// - Make a jQuery element for a list item
|
||||||
_makeListItemElement: function(sLabel, sValue, bInitChecked, bInitHidden,bObsolete, sAdditionalField)
|
_makeListItemElement: function(sLabel, sValue, bInitChecked, bInitHidden,bObsolete, sAdditionalField)
|
||||||
{
|
{
|
||||||
var sEscapedLabel = $('<div />').text(sLabel).html();
|
var sEscapedLabel = CombodoSanitizer.EscapeHtml(sLabel, false);
|
||||||
if (bObsolete == 1) {
|
if (bObsolete == 1) {
|
||||||
sEscapedLabel = '<span class="object-ref-icon text_decoration"><span class="fas fa-eye-slash object-obsolete fa-1x fa-fw"></span></span>'+sEscapedLabel;
|
sEscapedLabel = '<span class="object-ref-icon text_decoration"><span class="fas fa-eye-slash object-obsolete fa-1x fa-fw"></span></span>'+sEscapedLabel;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (sAdditionalField != undefined ) {
|
if (sAdditionalField != undefined ) {
|
||||||
sEscapedLabel = sEscapedLabel+'<br><i>'+sAdditionalField+'</i>';
|
sEscapedLabel = sEscapedLabel+'<br><i>'+CombodoSanitizer.EscapeHtml(sAdditionalField, false)+'</i>';
|
||||||
}
|
}
|
||||||
|
|
||||||
var oItemElem = $('<div></div>')
|
var oItemElem = $('<div></div>')
|
||||||
|
|||||||
Reference in New Issue
Block a user