diff options
author | Ivan Kohler <ivan@freeside.biz> | 2012-11-11 22:20:19 -0800 |
---|---|---|
committer | Ivan Kohler <ivan@freeside.biz> | 2012-11-11 22:20:19 -0800 |
commit | b2101823682f3738f5b367d2c1f2a7c6d47cdad1 (patch) | |
tree | 861ad1cfbf0db4279ccef14a3a6967376e4751a7 /httemplate/browse/part_event.html | |
parent | f06a0610477b0ba8e1931722c3105b880fbc35c3 (diff) |
fix XSS
Diffstat (limited to 'httemplate/browse/part_event.html')
-rw-r--r-- | httemplate/browse/part_event.html | 14 |
1 files changed, 7 insertions, 7 deletions
diff --git a/httemplate/browse/part_event.html b/httemplate/browse/part_event.html index c06a14fe7..62e7ff0d9 100644 --- a/httemplate/browse/part_event.html +++ b/httemplate/browse/part_event.html @@ -47,7 +47,7 @@ my $event_sub = sub { my $onclick = include('/elements/popup_link_onclick.html', action => $p.'view/part_event-targets.html?eventpart='. $part_event->eventpart, - actionlabel => 'Event query - '.$part_event->event, + actionlabel => 'Event query', #no, XSS - '.$part_event->event, width => 650, height => 420, close_text => 'Close', @@ -55,14 +55,14 @@ my $event_sub = sub { [#rows [#subcolumns { - 'data' => $part_event->event, - 'link' => $p.'edit/part_event.html?'.$part_event->eventpart, + 'data' => encode_entities($part_event->event), + 'link' => $p.'edit/part_event.html?'.$part_event->eventpart, }, { - 'data' => ' (query) ', - 'size' => '-1', - 'data_style' => 'b', - 'onclick' => $onclick, + 'data' => ' (query) ', + 'size' => '-1', + 'data_style' => 'b', + 'onclick' => $onclick, }, ], ]; |