diff options
author | Mitch Jackson <mitch@freeside.biz> | 2018-10-27 12:05:19 -0400 |
---|---|---|
committer | Mitch Jackson <mitch@freeside.biz> | 2018-10-27 12:11:23 -0400 |
commit | dd769e3736c49fa4cedf16f13db3a58cc7573cbb (patch) | |
tree | 40669fb522150bbb309ebbe4142d694e18ee9cac /httemplate | |
parent | 8120b9af43dac87f1a41ac3c8434465517235a25 (diff) |
RT# 79353 Fix XSS
Diffstat (limited to 'httemplate')
-rw-r--r-- | httemplate/search/cust_bill_pkg_discount.html | 6 |
1 files changed, 3 insertions, 3 deletions
diff --git a/httemplate/search/cust_bill_pkg_discount.html b/httemplate/search/cust_bill_pkg_discount.html index 691a11e60..9ddc97da2 100644 --- a/httemplate/search/cust_bill_pkg_discount.html +++ b/httemplate/search/cust_bill_pkg_discount.html @@ -39,8 +39,8 @@ Parameters: # Standard discount, not a waived setup fee my $discount = qsearchs('discount',{ discountnum => $_[0]->discountnum - }); - return $discount->description; + }) || return 'Bad discountnum '.$_[0]->pkgdiscountnum; + return encode_entities $discount->description; } else { return 'Waive setup fee'; } @@ -53,7 +53,7 @@ Parameters: my $discount = qsearchs('discount',{ discountnum => $_[0]->discountnum }); - return $discount->classname; + return encode_entities $discount->classname; } else { return 'n/a'; } |