From 5c748b9dcdbb602720d7cb6c8afa5087585d5caa Mon Sep 17 00:00:00 2001 From: notfenixio <103071021+NotFenixio@users.noreply.github.com> Date: Tue, 21 Nov 2023 19:08:25 +0100 Subject: [PATCH] =?UTF-8?q?=F0=9F=9B=A1=EF=B8=8F=20Security:=20Solve=20sec?= =?UTF-8?q?urity=20issue?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit This commit corrects a vulnerability discovered by CodeQL. The vulnerability could allow a malicious user to execute arbitrary code server-side. --- src/routes/feedback/+page.server.ts | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/routes/feedback/+page.server.ts b/src/routes/feedback/+page.server.ts index 4d564dc..9c2fdd4 100644 --- a/src/routes/feedback/+page.server.ts +++ b/src/routes/feedback/+page.server.ts @@ -5,6 +5,6 @@ export const actions = { const data = await request.formData(); const feedback = data.get('feedback'); - console.log(feedback?.toString().replace("\n", " ")); + console.log(feedback?.toString().replace(/\n/g, " ")); } -} satisfies Actions \ No newline at end of file +} satisfies Actions