From 6a48e0211dec6ec2d5a73ad1982682b744fb3474 Mon Sep 17 00:00:00 2001 From: David Lawrence Date: Tue, 10 May 2016 13:52:59 +0000 Subject: Bug 1271635 - XSS when viewing image attachments --- extensions/BugModal/web/bug_modal.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'extensions') diff --git a/extensions/BugModal/web/bug_modal.js b/extensions/BugModal/web/bug_modal.js index 2d7bb4764..e0ef40a13 100644 --- a/extensions/BugModal/web/bug_modal.js +++ b/extensions/BugModal/web/bug_modal.js @@ -1373,7 +1373,7 @@ function lb_show(el) { .addClass('minor') .text('Close') .appendTo(overlay2); - title.append(el.title); + title.text(el.title); overlay.add(overlay2).click(lb_close); img.add(overlay).animate({ opacity: 1 }, 200); } -- cgit v1.2.3-24-g4f1b