Queries: fix potential DOM text reinterpreted as HTML issue

Signed-off-by: XhmikosR <xhmikosr@gmail.com>
This commit is contained in:
XhmikosR
2025-03-23 09:34:48 +02:00
parent 877d5f8cb9
commit bd693fad80

View File

@@ -584,7 +584,9 @@ $(function () {
const dnssec = parseDNSSEC(data);
// Remove HTML from querystatus.fieldtext
var rawtext = $("<div/>").html(querystatus.fieldtext).text();
const tempDiv = document.createElement("div");
tempDiv.innerHTML = querystatus.fieldtext;
const rawtext = utils.escapeHtml(tempDiv.textContent || "");
if (querystatus.icon !== false) {
$("td:eq(1)", row).html(