Fix xss vulnerability

This commit is contained in:
Dmitriy Zaporozhets 2013-01-07 11:32:12 +02:00
parent 1665a06fdd
commit 676a9a7e28

View file

@ -88,5 +88,5 @@
%h4.nothing_here_message No wiki pages
:javascript
$(function() {
$(".search_results .term").highlight("#{params[:search]}");
$(".search_results .term").highlight("#{escape_javascript(params[:search])}");
})