luci-mod-admin-full: escape display parameter
authorJo-Philipp Wich <jo@mein.io>
Thu, 5 Apr 2018 21:00:46 +0000 (23:00 +0200)
committerJo-Philipp Wich <jo@mein.io>
Thu, 5 Apr 2018 21:03:01 +0000 (23:03 +0200)
commitbfc98bec4d79efb24434e11ea27b3c17c31365ab
tree97a72c7817cb566283bf5485eb20ccd4dbe8e543
parent731ed77c0bbee7004a6b5645d9a8592a76748a1c
luci-mod-admin-full: escape display parameter

Prevent reflected XSS through the reset button by url encoding the
display parameter.

Signed-off-by: Jo-Philipp Wich <jo@mein.io>
modules/luci-mod-admin-full/luasrc/view/admin_system/packages.htm