Merge pull request #1 from arjunshibu/master
Security fix for Cross-Site Scripting Vulnerability in frappe-charts
This commit is contained in:
commit
2fb0609a02
@ -110,7 +110,7 @@ export default class AxisChart extends BaseChart {
|
|||||||
let values = d.values;
|
let values = d.values;
|
||||||
let cumulativeYs = d.cumulativeYs || [];
|
let cumulativeYs = d.cumulativeYs || [];
|
||||||
return {
|
return {
|
||||||
name: d.name,
|
name: d.name.replace(/<|>|&/g, (char) => char == '&' ? '&' : char == '<' ? '<' : '>'),
|
||||||
index: i,
|
index: i,
|
||||||
chartType: d.chartType,
|
chartType: d.chartType,
|
||||||
|
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user