Skip to content

Commit

Permalink
xss 4
Browse files Browse the repository at this point in the history
  • Loading branch information
3r1s-s committed Oct 19, 2024
1 parent 3f4b119 commit af4c657
Showing 1 changed file with 6 additions and 4 deletions.
10 changes: 6 additions & 4 deletions script.js
Original file line number Diff line number Diff line change
Expand Up @@ -3896,7 +3896,7 @@ function cancelEdit() {

function openImage(url) {
const baseURL = url.split('?')[0];
const fileName = baseURL.split('/').pop();
const fileName = escapeHTML(baseURL.split('/').pop());

document.documentElement.style.overflow = "hidden";
const mdlbck = document.querySelector('.image-back');
Expand All @@ -3907,16 +3907,18 @@ function openImage(url) {
const mdl = mdlbck.querySelector('.image-mdl');
if (mdl) {
mdl.innerHTML = `
<img class='embed-large' src='${url}' alt="${fileName}" onclick='preventClose(event)'>
<img class='embed-large' src='${escapeHTML(url)}' alt="${fileName}" onclick='preventClose(event)'>
<div class="img-links">
<span class="img-link-outer"><a onclick="closeImage()" class="img-link">${lang().action.close}</a></span>
<span><a href="${url}?download" target="_blank" class="img-link">${lang().action.download}</a></span>
<span class="img-link-outer"><a onclick="closeImage()" class="img-link">${escapeHTML(lang().action.close)}</a></span>
<span><a href="${escapeHTML(url)}?download" target="_blank" class="img-link">${escapeHTML(lang().action.download)}</a></span>
</div>
`;
}
}
}

// making ai do this i literally cant be bothered

function preventClose(event) {
event.stopPropagation();
}
Expand Down

0 comments on commit af4c657

Please sign in to comment.