diff --git a/app/src/Server.js b/app/src/Server.js
index 7677d9c1..5225d6b9 100644
--- a/app/src/Server.js
+++ b/app/src/Server.js
@@ -55,7 +55,7 @@ dev dependencies: {
* @license For commercial or closed source, contact us at license.mirotalk@gmail.com or purchase directly via CodeCanyon
* @license CodeCanyon: https://codecanyon.net/item/mirotalk-sfu-webrtc-realtime-video-conferences/40769970
* @author Miroslav Pejic - miroslav.pejic.85@gmail.com
- * @version 1.6.69
+ * @version 1.6.70
*
*/
@@ -607,7 +607,7 @@ function startServer() {
// join room by id
app.get('/join/:roomId', async (req, res) => {
//
- const { roomId } = req.params;
+ const { roomId } = checkXSS(req.params);
if (!roomId) {
log.warn('/join/:roomId empty', roomId);
@@ -752,7 +752,7 @@ function startServer() {
if (serverRecordingEnabled) {
//
try {
- const { fileName } = req.query;
+ const { fileName } = checkXSS(req.query);
if (!fileName) {
return res.status(400).send('Filename not provided');
diff --git a/package.json b/package.json
index 0d2e654e..efc063bf 100644
--- a/package.json
+++ b/package.json
@@ -1,6 +1,6 @@
{
"name": "mirotalksfu",
- "version": "1.6.69",
+ "version": "1.6.70",
"description": "WebRTC SFU browser-based video calls",
"main": "Server.js",
"scripts": {
diff --git a/public/js/Room.js b/public/js/Room.js
index 71734406..9868ae54 100644
--- a/public/js/Room.js
+++ b/public/js/Room.js
@@ -11,7 +11,7 @@ if (location.href.substr(0, 5) !== 'https') location.href = 'https' + location.h
* @license For commercial or closed source, contact us at license.mirotalk@gmail.com or purchase directly via CodeCanyon
* @license CodeCanyon: https://codecanyon.net/item/mirotalk-sfu-webrtc-realtime-video-conferences/40769970
* @author Miroslav Pejic - miroslav.pejic.85@gmail.com
- * @version 1.6.69
+ * @version 1.6.70
*
*/
@@ -4618,7 +4618,7 @@ function showAbout() {
imageUrl: image.about,
customClass: { image: 'img-about' },
position: 'center',
- title: 'WebRTC SFU v1.6.69',
+ title: 'WebRTC SFU v1.6.70',
html: `