JLyne / LiveAtlas

A Dynmap, Squaremap, Pl3xmap and Overviewer frontend for the modern web
Apache License 2.0
336 stars 37 forks source link

Squaremap-signs injection attack vector #628

Closed CodexNotFound closed 1 year ago

CodexNotFound commented 1 year ago

I'm replacing the <br/>s by uuddlrlrbaStartSelect (Konami code). The reason for this is because it's long enough to not fit on a sign and thus safe to use.

I don't run Dynmap so I'm not sure if that issue would be happening there as well.

Fixes #627