mirror of
https://github.com/Sea-Haven-Industries/procurement-ingest.git
synced 2026-10-01 22:08:00 +00:00
Both Function URLs are public (auth_type=NONE) and render email-derived content via f-strings. Attacker-crafted emails could inject scripts. Added html.escape() on all interpolated values in both PO and WO dashboards. |
||
|---|---|---|
| .. | ||
| email_processor | ||
| site_extractor | ||
| web_ui | ||