mirror of
https://github.com/Sea-Haven-Industries/procurement-ingest.git
synced 2026-10-02 03:53:26 +00:00
Both Function URLs are public (auth_type=NONE) and render email-derived content via f-strings. Attacker-crafted emails could inject scripts. Added html.escape() on all interpolated values in both PO and WO dashboards. |
||
|---|---|---|
| .. | ||
| handler.py | ||