Security: Remove possible XSS when showing file name selected

pull/4973/merge
Angel Fernando Quiroz Campos 2 years ago
parent 78d9462b1f
commit a63e03ef96
  1. 2
      main/inc/lib/pear/HTML/QuickForm/file.php

@ -460,7 +460,7 @@ class HTML_QuickForm_file extends HTML_QuickForm_input
if (this.files[0]) { if (this.files[0]) {
fileName = this.files[0].name; fileName = this.files[0].name;
} }
the_return.innerHTML = fileName; the_return.textContent = fileName;
}); });
</script> </script>
'; ';

Loading…
Cancel
Save