Fix security issue with markdown, thanks to @simhnna

This commit is contained in:
James Cole
2018-04-04 19:14:47 +02:00
parent 73fee4eb6b
commit 3819de4e74
5 changed files with 27 additions and 11 deletions

View File

@@ -84,11 +84,11 @@
<h3 class="box-title">{{ 'more'|_ }}</h3>
</div>
<div class="box-body no-padding">
{% if object.notes|length > 0 %}
{% if object.data.notes|length > 0 %}
<table class="table">
<tr>
<td>{{ trans('list.notes') }}</td>
<td class="markdown">{{ object.notes.data[0].markdown }}</td>
<td class="markdown">{{ object.data.notes|markdown }}</td>
</tr>
</table>
{% endif %}