xss
authorIvan Kohler <ivan@freeside.biz>
Thu, 10 Mar 2016 00:10:59 +0000 (16:10 -0800)
committerIvan Kohler <ivan@freeside.biz>
Thu, 10 Mar 2016 00:10:59 +0000 (16:10 -0800)
httemplate/search/quotation.html

index 2eba71c..16affeb 100755 (executable)
@@ -27,7 +27,7 @@
                          $prospect_main ? $prospect_main->name : '';
                        },
                    sub { my $cust_main = shift->cust_main;
-                         $cust_main ? $cust_main->name : '';
+                         $cust_main ? encode_entities($cust_main->name) : '';
                        },
                    'confidence',
                    sub { my $quot = shift;