Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- sanitize the message when it was provided as a parameter - this is to prevent XSS vulnerability such as UniTime/main.action?message=%3Cscript%3Ealert(%22test%22);%3C/script%3E - system and logout messages may still contain HTML tags
- Loading branch information