Skip to content
Permalink
Browse files

Fix potential XSS issue with [layers] tag.

  • Loading branch information...
sdlime authored and rouault committed Apr 17, 2019
1 parent 8ad2301 commit fe08631bcdf54ada918cda22214aa2b5a6ec19cb
Showing with 3 additions and 1 deletion.
  1. +3 −1 maptemplate.c
@@ -3671,7 +3671,9 @@ static char *processLine(mapservObj *mapserv, char *instr, FILE *stream, int mod
strlcat(repstr, " ", sizeof(repstr));
}
msStringTrimBlanks(repstr);
outstr = msReplaceSubstring(outstr, "[layers]", repstr);
encodedstr = msEncodeHTMLEntities(repstr);
outstr = msReplaceSubstring(outstr, "[layers]", encodedstr);
free(encodedstr);

encodedstr = msEncodeUrl(repstr);
outstr = msReplaceSubstring(outstr, "[layers_esc]", encodedstr);

0 comments on commit fe08631

Please sign in to comment.
You can’t perform that action at this time.