Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Submit feedback
Sign in
Toggle navigation
F
flask-admin
Project
Project
Details
Activity
Releases
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
JIRA
JIRA
Merge Requests
0
Merge Requests
0
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Commits
Issue Boards
Open sidebar
Python-Dev
flask-admin
Commits
f447db0c
Commit
f447db0c
authored
Aug 20, 2015
by
Paul Brown
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
fix xss vulnerability - escape html in column_editable_list values
parent
691a1c98
Changes
1
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
3 additions
and
1 deletion
+3
-1
widgets.py
flask_admin/model/widgets.py
+3
-1
No files found.
flask_admin/model/widgets.py
View file @
f447db0c
from
flask
import
json
from
jinja2
import
escape
from
wtforms.widgets
import
HTMLString
,
html_params
from
flask_admin._compat
import
as_unicode
...
...
@@ -92,7 +93,8 @@ class XEditableWidget(object):
kwargs
=
self
.
get_kwargs
(
subfield
,
kwargs
)
return
HTMLString
(
'<a
%
s>
%
s</a>'
%
(
html_params
(
**
kwargs
),
kwargs
[
'data-value'
])
'<a
%
s>
%
s</a>'
%
(
html_params
(
**
kwargs
),
escape
(
kwargs
[
'data-value'
]))
)
def
get_kwargs
(
self
,
subfield
,
kwargs
):
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment