Changeset 470


Ignore:
Timestamp:
05/05/20 12:19:08 (4 years ago)
Author:
nanardon
Message:

Fix possible xss injection (Chris Lamb <lamby@…>)

File:
1 edited

Legend:

Unmodified
Added
Removed
  • web/root/templates/html/search/simple_search.tt

    r322 r470  
    22<div id="sophie_header_search"> 
    33    <form action="[% c.uri_for('/search/results') %]"> 
    4         <input type="text" name="search" value="[% c.req.param('search') %]"> 
     4        <input type="text" name="search" value="[% c.req.param('search') | html %]"> 
    55        <input type="image" 
    66            src="[% c.uri_for('/static/images', 'search.png') %]" 
Note: See TracChangeset for help on using the changeset viewer.