Sanitize report name in pdf.php (#10270)

Authentication users could include arbitrary file.
This commit is contained in:
Tony Murray
2019-05-29 09:39:17 -05:00
committed by GitHub
parent f14b90a1ef
commit 54e4d0910a
5 changed files with 95 additions and 46 deletions

View File

@@ -51,7 +51,7 @@ class NotesController extends WidgetController
'HTML.SafeIframe' => true,
'URI.SafeIframeRegexp' => '%^(https?:)?//%',
];
$output = Html::display(nl2br($settings['notes']), $purifier_config);
$output = \LibreNMS\Util\Clean::html(nl2br($settings['notes']), $purifier_config);
return $output;
}