mirror of
https://github.com/Ylianst/MeshCentral.git
synced 2024-11-22 12:52:50 +03:00
04c96eb2ff
* Fixed filenames not being escaped when editing files This allowed a possible XSS by naming a file in a particular way on your device. * Fixed HTML generation in webserver not escaping most things from req.query This would allow XSS through a very simple phishing attack * Added HtmlEscape to Mobile default as well * Added sanitization to SAML redirect and Twitter/Azure |
||
---|---|---|
.. | ||
agentinvite.handlebars | ||
default-mobile.handlebars | ||
default.handlebars | ||
download2.handlebars | ||
download.handlebars | ||
error404-mobile.handlebars | ||
error404.handlebars | ||
error4042.handlebars | ||
invite.handlebars | ||
login2.handlebars | ||
login-mobile.handlebars | ||
login.handlebars | ||
message2.handlebars | ||
message.handlebars | ||
messenger.handlebars | ||
mstsc.handlebars | ||
player.handlebars | ||
sharing-mobile.handlebars | ||
sharing.handlebars | ||
ssh.handlebars | ||
terms-mobile.handlebars | ||
terms.handlebars | ||
xterm.handlebars |