diff --git a/web/dashboard/templates/dashboard/admin.html b/web/dashboard/templates/dashboard/admin.html
index a9008afd2..e7452084f 100644
--- a/web/dashboard/templates/dashboard/admin.html
+++ b/web/dashboard/templates/dashboard/admin.html
@@ -67,9 +67,9 @@
Users
{% if muser.get_full_name %}
- {{muser.get_full_name}}
+ {{muser.get_full_name|escape}}
{% else %}
- {{muser.username}}
+ {{muser.username|escape}}
{% endif %}
|
@@ -128,7 +128,7 @@ Users
function delete_user(id, username) {
const delAPI = "./update?mode=delete&user=" + id;
swal.queue([{
- title: 'Are you sure you want to delete user '+ username +'?',
+ title: 'Are you sure you want to delete user '+ htmlEncode(username) +'?',
text: "You won't be able to revert this!",
type: 'warning',
showCancelButton: true,
@@ -313,7 +313,7 @@ Users
Swal.fire({
title: "Oops! Can't create user!",
icon: 'error',
- text: 'Error: ' + data.error,
+ text: 'Error: ' + htmlEncode(data.error),
})
}
|