mirror of
https://github.com/PegaProx/project-pegaprox.git
synced 2026-08-12 15:27:47 +08:00
fmtTime() returned the raw input string when a value did not parse as a date, and that string is concatenated into the incident HTML. A malicious admin could store markup (e.g. a <link>/<img> to an attacker HTTPS resource) in started_at/resolved_at and force viewers to load it. Route the fallback through the existing escapeHtml helper; valid dates still render via toLocaleString. (Aikido low #338694499)