Commit 1a4803a6 authored by Tom Evans's avatar Tom Evans Committed by tevans

OF-671: Prevent XSS for domain attribute on s2s config page

git-svn-id: http://svn.igniterealtime.org/svn/repos/openfire/trunk@13647 b35dd754-fafc-0310-a699-88a17e54d16e
parent 3b014d02
...@@ -46,6 +46,10 @@ ...@@ -46,6 +46,10 @@
boolean serverAllowed = request.getParameter("serverAllowed") != null; boolean serverAllowed = request.getParameter("serverAllowed") != null;
boolean serverBlocked = request.getParameter("serverBlocked") != null; boolean serverBlocked = request.getParameter("serverBlocked") != null;
String domain = ParamUtils.getParameter(request,"domain"); String domain = ParamUtils.getParameter(request,"domain");
// OF-671
if (domain != null) {
domain = StringUtils.removeXSSCharacters(domain);
}
String remotePort = ParamUtils.getParameter(request,"remotePort"); String remotePort = ParamUtils.getParameter(request,"remotePort");
boolean updateSucess = false; boolean updateSucess = false;
boolean allowSuccess = false; boolean allowSuccess = false;
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment