summaryrefslogtreecommitdiff
path: root/gitweb
diff options
context:
space:
mode:
authorJeff King <peff@peff.net>2012-11-12 16:34:28 -0500
committerJeff King <peff@peff.net>2012-11-12 16:34:53 -0500
commit0f0ecf68b31303de7cb428554e27d433fe62180e (patch)
treed1f8f5902fb5ff6dd45ba21e6fce2a5d6e7f185d /gitweb
parent7e2010537e96d0a1144520222f20ba1dc3d61441 (diff)
downloadgit-0f0ecf68b31303de7cb428554e27d433fe62180e.tar.gz
gitweb: escape html in rss title
The title of an RSS feed is generated from many components, including the filename provided as a query parameter, but we failed to quote it. Besides showing the wrong output, this is a vector for XSS attacks. Signed-off-by: Jeff King <peff@peff.net>
Diffstat (limited to 'gitweb')
-rwxr-xr-xgitweb/gitweb.perl1
1 files changed, 1 insertions, 0 deletions
diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl
index 10ed9e51a5..a51a8babee 100755
--- a/gitweb/gitweb.perl
+++ b/gitweb/gitweb.perl
@@ -8055,6 +8055,7 @@ sub git_feed {
$feed_type = 'history';
}
$title .= " $feed_type";
+ $title = esc_html($title);
my $descr = git_get_project_description($project);
if (defined $descr) {
$descr = esc_html($descr);