From 3c15a4f4aad498189463d9205fc546c57598af22 Mon Sep 17 00:00:00 2001 From: Elijah R Date: Fri, 19 Jul 2024 16:07:21 -0400 Subject: [PATCH] fix xss vulnerability --- EmperorPalpatine/VM.cs | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/EmperorPalpatine/VM.cs b/EmperorPalpatine/VM.cs index b6e3fe8..38c895f 100644 --- a/EmperorPalpatine/VM.cs +++ b/EmperorPalpatine/VM.cs @@ -64,7 +64,7 @@ public class VM await cvm.SendChat($"@{username} No messages found for {args[0]}"); return; } - await cvm.SendXSSChat($"\"{chat[0].Message}\" - {chat[0].Username}"); + await cvm.SendXSSChat($"\"{WebUtility.HtmlEncode(chat[0].Message)}\" - {chat[0].Username}"); } private void CvmOnConnectionClosed(object? sender, EventArgs e)