diff options
| author | Mitch Jackson <mitch@freeside.biz> | 2018-10-27 12:05:19 -0400 | 
|---|---|---|
| committer | Mitch Jackson <mitch@freeside.biz> | 2018-10-27 12:11:23 -0400 | 
| commit | dd769e3736c49fa4cedf16f13db3a58cc7573cbb (patch) | |
| tree | 40669fb522150bbb309ebbe4142d694e18ee9cac /httemplate | |
| parent | 8120b9af43dac87f1a41ac3c8434465517235a25 (diff) | |
RT# 79353 Fix XSS
Diffstat (limited to 'httemplate')
| -rw-r--r-- | httemplate/search/cust_bill_pkg_discount.html | 6 | 
1 files changed, 3 insertions, 3 deletions
| diff --git a/httemplate/search/cust_bill_pkg_discount.html b/httemplate/search/cust_bill_pkg_discount.html index 691a11e60..9ddc97da2 100644 --- a/httemplate/search/cust_bill_pkg_discount.html +++ b/httemplate/search/cust_bill_pkg_discount.html @@ -39,8 +39,8 @@ Parameters:              # Standard discount, not a waived setup fee              my $discount = qsearchs('discount',{                  discountnum => $_[0]->discountnum -            }); -            return $discount->description; +            }) || return 'Bad discountnum '.$_[0]->pkgdiscountnum; +            return encode_entities $discount->description;          } else {              return 'Waive setup fee';          } @@ -53,7 +53,7 @@ Parameters:              my $discount = qsearchs('discount',{                  discountnum => $_[0]->discountnum              }); -            return $discount->classname; +            return encode_entities $discount->classname;          } else {              return 'n/a';          } | 
