From: Jeff King Date: Mon, 12 Nov 2012 21:34:28 +0000 (-0500) Subject: gitweb: escape html in rss title X-Git-Url: https://git.ladys.computer/Gitweb/commitdiff_plain/f3ddf5b87f42b68fad2aebdbbae36f5429051434461615ec57f828442f1c5259?ds=inline gitweb: escape html in rss title The title of an RSS feed is generated from many components, including the filename provided as a query parameter, but we failed to quote it. Besides showing the wrong output, this is a vector for XSS attacks. Signed-off-by: Jeff King --- diff --git a/gitweb.perl b/gitweb.perl index b9ceaf9..8d9e568 100755 --- a/gitweb.perl +++ b/gitweb.perl @@ -8055,6 +8055,7 @@ sub git_feed { $feed_type = 'history'; } $title .= " $feed_type"; + $title = esc_html($title); my $descr = git_get_project_description($project); if (defined $descr) { $descr = esc_html($descr);