From 0a88db50d6a6c9c1917c4e7a6e67a467d2b5f84b Mon Sep 17 00:00:00 2001 From: conradverm Date: Fri, 13 Jul 2007 15:05:43 +0000 Subject: [PATCH] KTS-2178 "cross site scripting" Updated. --- plugins/rssplugin/templates/RSSPlugin/dashlet.smarty | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/plugins/rssplugin/templates/RSSPlugin/dashlet.smarty b/plugins/rssplugin/templates/RSSPlugin/dashlet.smarty index a0b5a8c..a68f89c 100644 --- a/plugins/rssplugin/templates/RSSPlugin/dashlet.smarty +++ b/plugins/rssplugin/templates/RSSPlugin/dashlet.smarty @@ -9,13 +9,13 @@ {/if} {if $feedlist} {section name=feed loop=$feedlist} - + {/section} {/if} {if ($action.url)}{$action.name}{else}{$action.name}{/if} +{if $action.description}title="{$action.description|sanitize}"{/if} + >{$action.name}{else}{$action.name|sanitize}{/if} {/if} @@ -26,7 +26,7 @@ {section name=i start=0 loop=$itemcount} - + -- libgit2 0.21.4
{$internalrss.items[i].title}{$internalrss.items[i].title|sanitize}
{$internalrss.items[i].description}