New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Mitigate potential cross site scripting issues on SlickGrid view #465
Comments
amercader
added a commit
to ckan/ckan
that referenced
this issue
Feb 25, 2015
See datopian/datahub#465 for details Patching local recline but a PR has been sent to the recline repo: datopian/datahub#466
rufuspollock
added a commit
that referenced
this issue
Feb 25, 2015
Sanitize header name on SlickGrid view. Fixes #465
amercader
added a commit
to ckan/ckan
that referenced
this issue
Feb 26, 2015
See datopian/datahub#465 for details Patching local recline but a PR has been sent to the recline repo: datopian/datahub#466
amercader
added a commit
to ckan/ckan
that referenced
this issue
Feb 26, 2015
See datopian/datahub#465 for details Patching local recline but a PR has been sent to the recline repo: datopian/datahub#466
amercader
added a commit
to ckan/ckan
that referenced
this issue
Feb 26, 2015
See datopian/datahub#465 for details Patching local recline but a PR has been sent to the recline repo: datopian/datahub#466
amercader
added a commit
to ckan/ckan
that referenced
this issue
Feb 26, 2015
See datopian/datahub#465 for details Patching local recline but a PR has been sent to the recline repo: datopian/datahub#466
rufuspollock
added a commit
that referenced
this issue
Apr 9, 2016
…lickgrid-view [#465] Sanitize header name on SlickGrid view
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
SlickGrid will use
$.html
to render the header cell contents.This means that if you are loading an external dodgy CSV like the following one, scripts will be evaluated:
Quickest fix is to sanitize the label when initializing SlickGrid
The text was updated successfully, but these errors were encountered: