Files: Fix XSS when creating dropshadow
This commit is contained in:
parent
2314067e75
commit
1507d1ef26
|
@ -757,9 +757,9 @@ var createDragShadow = function(event){
|
||||||
var dir=$('#dir').val();
|
var dir=$('#dir').val();
|
||||||
|
|
||||||
$(selectedFiles).each(function(i,elem){
|
$(selectedFiles).each(function(i,elem){
|
||||||
var newtr = $('<tr data-dir="'+dir+'" data-filename="'+elem.name+'">'
|
var newtr = $('<tr/>').attr('data-dir', dir).attr('data-filename', elem.name);
|
||||||
+'<td class="filename">'+elem.name+'</td><td class="size">'+humanFileSize(elem.size)+'</td>'
|
newtr.append($('<td/>').addClass('filename').text(elem.name));
|
||||||
+'</tr>');
|
newtr.append($('<td/>').addClass('size').text(humanFileSize(elem.size)));
|
||||||
tbody.append(newtr);
|
tbody.append(newtr);
|
||||||
if (elem.type === 'dir') {
|
if (elem.type === 'dir') {
|
||||||
newtr.find('td.filename').attr('style','background-image:url('+OC.imagePath('core', 'filetypes/folder.png')+')');
|
newtr.find('td.filename').attr('style','background-image:url('+OC.imagePath('core', 'filetypes/folder.png')+')');
|
||||||
|
|
Loading…
Reference in New Issue