From dcdfb4a8baa4a65805713e7a5437f33c2c64cbfc Mon Sep 17 00:00:00 2001 From: Marty-D Date: Wed, 21 Oct 2015 11:14:08 -0400 Subject: [PATCH] Fix XSS vulnerability in previous version of `-fail unboost` --- js/battle.js | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/js/battle.js b/js/battle.js index 0b832768a..af837d415 100644 --- a/js/battle.js +++ b/js/battle.js @@ -3758,7 +3758,8 @@ var Battle = (function () { actions += '' + ofpoke.getName() + ' surrounded itself with a veil of petals!'; break; default: - actions += "" + poke.getName() + "'s " + (args[3] ? args[3] + " was" : "stats were") + " not lowered!"; + var stat = Tools.escapeHTML(args[3]); + actions += "" + poke.getName() + "'s " + (stat ? stat + " was" : "stats were") + " not lowered!"; } break; default: