Skip to content

Commit e8e2367

Browse files
author
Chris C Cerami
authored
Merge pull request #1687 from brianvans/queues_view_xss
Escape id parameter for queues view
2 parents 8b0bf00 + efe7ba1 commit e8e2367

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

lib/resque/server/views/queues.erb

+1-1
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22

33
<% if current_queue = params[:id] %>
44

5-
<h1>Pending jobs on <span class='hl'><%= current_queue %></span></h1>
5+
<h1>Pending jobs on <span class='hl'><%= h current_queue %></span></h1>
66
<form method="POST" action="<%=u "/queues/#{current_queue}/remove" %>" class='remove-queue'>
77
<input type='submit' name='' value='Remove Queue' onclick='return confirm("Are you absolutely sure? This cannot be undone.");' />
88
</form>

0 commit comments

Comments
 (0)