summaryrefslogtreecommitdiff
path: root/httemplate
diff options
context:
space:
mode:
authorMitch Jackson <mitch@freeside.biz>2018-10-27 12:05:19 -0400
committerMitch Jackson <mitch@freeside.biz>2018-10-27 12:11:23 -0400
commitdd769e3736c49fa4cedf16f13db3a58cc7573cbb (patch)
tree40669fb522150bbb309ebbe4142d694e18ee9cac /httemplate
parent8120b9af43dac87f1a41ac3c8434465517235a25 (diff)
RT# 79353 Fix XSS
Diffstat (limited to 'httemplate')
-rw-r--r--httemplate/search/cust_bill_pkg_discount.html6
1 files changed, 3 insertions, 3 deletions
diff --git a/httemplate/search/cust_bill_pkg_discount.html b/httemplate/search/cust_bill_pkg_discount.html
index 691a11e60..9ddc97da2 100644
--- a/httemplate/search/cust_bill_pkg_discount.html
+++ b/httemplate/search/cust_bill_pkg_discount.html
@@ -39,8 +39,8 @@ Parameters:
# Standard discount, not a waived setup fee
my $discount = qsearchs('discount',{
discountnum => $_[0]->discountnum
- });
- return $discount->description;
+ }) || return 'Bad discountnum '.$_[0]->pkgdiscountnum;
+ return encode_entities $discount->description;
} else {
return 'Waive setup fee';
}
@@ -53,7 +53,7 @@ Parameters:
my $discount = qsearchs('discount',{
discountnum => $_[0]->discountnum
});
- return $discount->classname;
+ return encode_entities $discount->classname;
} else {
return 'n/a';
}