diff options
author | Ivan Kohler <ivan@freeside.biz> | 2013-11-17 17:10:06 -0800 |
---|---|---|
committer | Ivan Kohler <ivan@freeside.biz> | 2013-11-17 17:10:06 -0800 |
commit | d4cdc4db87f1b6a373398b7ab33e791bd0527dda (patch) | |
tree | 899459b98e0b15bee54d0b67a41e6eed189e199f /httemplate/edit/process/cust_main.cgi | |
parent | 0076a0d790d1385cd2a16472ec2c11528edbc9e3 (diff) |
don't redirect to a GET with sensitive data, RT#26099
Diffstat (limited to 'httemplate/edit/process/cust_main.cgi')
-rwxr-xr-x | httemplate/edit/process/cust_main.cgi | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/httemplate/edit/process/cust_main.cgi b/httemplate/edit/process/cust_main.cgi index ff8be1a71..4fb8f622d 100755 --- a/httemplate/edit/process/cust_main.cgi +++ b/httemplate/edit/process/cust_main.cgi @@ -1,7 +1,7 @@ % if ( $error ) { % $cgi->param('error', $error); -% -<% $cgi->redirect(popurl(2). "cust_main.cgi?". $cgi->query_string ) %> +% my $query = $m->scomp('/elements/create_uri_query', 'secure'=>1); +<% $cgi->redirect(popurl(2). "cust_main.cgi?$query" ) %> % % } else { % |