Skip to content

Commit dbce9db

Browse files
committed
codeql text/html injection in food.js
1 parent 1db4047 commit dbce9db

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

lib/food/food.js

+1-1
Original file line numberDiff line numberDiff line change
@@ -248,7 +248,7 @@ client.init(function loaded () {
248248
.append($('<span>').addClass('width50px').css('text-align','center').text(foodlist[i].unit))
249249
.append($('<span>').addClass('width100px').css('text-align','center').append(foodlist[i].carbs))
250250
.append($('<span>').addClass('width100px').css('text-align','center').append(foodlist[i].gi))
251-
.append($('<span>').addClass('width150px').append(foodlist[i].category))
251+
.append($('<span>').addClass('width150px').text(foodlist[i].category))
252252
.append($('<span>').addClass('width150px').text(foodlist[i].subcategory))
253253
.append($('<span>').addClass('width100px').append(foodlist[i].fat))
254254
.append($('<span>').addClass('width100px').append(foodlist[i].protein))

0 commit comments

Comments
 (0)