mirror of
https://github.com/overleaf/overleaf.git
synced 2024-11-21 20:47:08 -05:00
7f7b10aa09
When showing system-messages, use default Angular sanitizer, also, on the admin panel itself, show the verbatim text of the message. This solves a mild Stored-XSS vulnerability whereby a user could put `<script>` tags in a message. We don't want that, but we do want to be able to use basic html tags. |
||
---|---|---|
.. | ||
coffee | ||
font | ||
img | ||
js | ||
recurly | ||
stylesheets | ||
apple-touch-icon-precomposed.png | ||
favicon.ico | ||
humans.txt | ||
mask-favicon.svg | ||
ol-apple-touch-icon-precomposed.png | ||
ol-favicon.ico | ||
ol-mask-favicon.svg | ||
ol-touch-icon-192x192.png | ||
robots.txt | ||
sharelatex-security.pub | ||
touch-icon-192x192.png |