mirror of
https://github.com/librenms/librenms.git
synced 2024-10-07 16:52:45 +00:00
Sanitize report name in pdf.php (#10270)
Authentication users could include arbitrary file.
This commit is contained in:
@@ -51,7 +51,7 @@ class NotesController extends WidgetController
|
||||
'HTML.SafeIframe' => true,
|
||||
'URI.SafeIframeRegexp' => '%^(https?:)?//%',
|
||||
];
|
||||
$output = Html::display(nl2br($settings['notes']), $purifier_config);
|
||||
$output = \LibreNMS\Util\Clean::html(nl2br($settings['notes']), $purifier_config);
|
||||
|
||||
return $output;
|
||||
}
|
||||
|
Reference in New Issue
Block a user