patch XSS, injection vuln
This commit is contained in:
@ -1,3 +1,4 @@
|
||||
import DOMPurify from 'isomorphic-dompurify';
|
||||
import React, { useState } from 'react';
|
||||
import { FormattedMessage } from 'react-intl';
|
||||
|
||||
@ -57,7 +58,7 @@ const About: React.FC<IAbout> = ({ slug }) => {
|
||||
<div>
|
||||
<Card variant='rounded'>
|
||||
<div className='prose mx-auto py-4 dark:prose-invert sm:p-6'>
|
||||
{pageHtml && <div dangerouslySetInnerHTML={{ __html: pageHtml }} />}
|
||||
{pageHtml && <div dangerouslySetInnerHTML={{ __html: DOMPurify.sanitize(pageHtml, { USE_PROFILES: { html: true } }) }} />}
|
||||
{alsoAvailable}
|
||||
</div>
|
||||
</Card>
|
||||
|
||||
Reference in New Issue
Block a user