mirror of https://github.com/Xhofe/alist
fix: reflected XSS vulnerability plist api
parent
34746e951c
commit
6100647310
|
@ -45,6 +45,8 @@ func Plist(c *gin.Context) {
|
||||||
}
|
}
|
||||||
fullName := c.Param("name")
|
fullName := c.Param("name")
|
||||||
Url := link.String()
|
Url := link.String()
|
||||||
|
Url = strings.ReplaceAll(Url, "<", "[")
|
||||||
|
Url = strings.ReplaceAll(Url, ">", "]")
|
||||||
nameEncode := linkNameSplit[1]
|
nameEncode := linkNameSplit[1]
|
||||||
fullName, err = url.PathUnescape(nameEncode)
|
fullName, err = url.PathUnescape(nameEncode)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
|
|
Loading…
Reference in New Issue