summaryrefslogtreecommitdiff
path: root/plugins/hitokoto
AgeCommit message (Collapse)Author
2021-11-11fix(plugins): fix potential command injection in `rand-quote` and `hitokoto`Marc Cornellà
The `rand-quote` plugin uses quotationspage.com and prints part of its content to the shell without sanitization, which could trigger command injection. There is no evidence that this has been exploited, but this commit removes all possibility for exploit. Similarly, the `hitokoto` plugin uses the hitokoto.cn website to print quotes to the shell, also without sanitization. Furthermore, there is also no evidence that this has been exploited, but with this change it is now impossible.
2019-12-28-mAdd hitokoto plugin (#8422)sinrimin