mirror of https://github.com/Xhofe/alist
fix: reflected XSS vulnerability plist api
parent
34746e951c
commit
6100647310
|
@ -45,6 +45,8 @@ func Plist(c *gin.Context) {
|
|||
}
|
||||
fullName := c.Param("name")
|
||||
Url := link.String()
|
||||
Url = strings.ReplaceAll(Url, "<", "[")
|
||||
Url = strings.ReplaceAll(Url, ">", "]")
|
||||
nameEncode := linkNameSplit[1]
|
||||
fullName, err = url.PathUnescape(nameEncode)
|
||||
if err != nil {
|
||||
|
|
Loading…
Reference in New Issue