Commit 67ca59ff authored by Shaposhnikov Ilya's avatar Shaposhnikov Ilya
Browse files

Fixed SSTI

parent 7c26db67
......@@ -2540,7 +2540,7 @@ def generate_report(project_id, current_project, current_user):
"grouped_issues": project_dict['grouped_issues'],
"docx_image": docx_image
},
autoescape=True
jinja_env=SandboxedEnvironment(autoescape=True)
)
template_obj.save(result_docx_path)
result_file = open(result_docx_path, 'rb')
......@@ -2601,7 +2601,7 @@ def generate_report(project_id, current_project, current_user):
print('Error reading ' + file_path)
f.close()
if template_data:
env = SandboxedEnvironment()
env = SandboxedEnvironment(autoescape=True)
template_obj = env.from_string(template_data)
project_dict = db.select_report_info_sorted(
current_project['id'])
......
Supports Markdown
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment