diff --git a/main.py b/main.py index fd03988..92ee2dc 100644 --- a/main.py +++ b/main.py @@ -1,5 +1,6 @@ import os import base64 +import html from flask import Flask, request from model import Message @@ -31,7 +32,7 @@ def home():
-""".format(m.content) +""".format(html.escape(m.content)) return body diff --git a/requirements.txt b/requirements.txt index b4ca511..7ff63ed 100644 --- a/requirements.txt +++ b/requirements.txt @@ -2,6 +2,6 @@ click==6.7 Flask==1.0.2 itsdangerous==0.24 Jinja2==2.10 -MarkupSafe==1.0 +MarkupSafe==1.1.1 peewee==3.3.4 Werkzeug==0.14.1