Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- enable HTML escaping for the message parameter - this is to prevent XSS vulnerability such as UniTime/main.action?message=%3Cscript%3Ealert(%22test%22);%3C/script%3E
- Loading branch information