Skip to content

Commit a05727e

Browse files
committed
Added minimal sanitization
-prevent at least some alternate solutions
1 parent b5f1788 commit a05727e

File tree

1 file changed

+1
-1
lines changed
  • injection/class-cancelled-3

1 file changed

+1
-1
lines changed

injection/class-cancelled-3/server

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ app = flask.Flask(__name__)
99
def post():
1010
username = flask.request.args.get("user")
1111
message = flask.request.args.get("message")
12-
#message = message.replace("\n", "<br>").replace("<", "(")
12+
message = message.replace("\n", "<br>") #minimal sanitization
1313
messages = f"{username},{message}\n" + open("messages.txt").read()
1414
open("messages.txt", "w").write(messages)
1515

0 commit comments

Comments
 (0)