Commit 9445dfcde1669ce2d56610c5f23bb1f0553f1d01
1 parent
11eb9e3b
Merged in from DEV trunk...
KTC-174, KTC-175, KTC-176
"In IE6: Only the first (none thereafter) external feed is created with the title: "><script>alert('hello');</script>""
Fixed. added sanitize to smarty file...
Committed By: Jalaloedien Abrahams
Reviewed By: Kevin Fourie
git-svn-id: https://kt-dms.svn.sourceforge.net/svnroot/kt-dms/STABLE/trunk@7044 c91229c3-7414-0410-bfa2-8a42b809f60b
Showing
1 changed file
with
1 additions
and
1 deletions
plugins/rssplugin/templates/RSSPlugin/managerssfeeds.smarty
| ... | ... | @@ -21,7 +21,7 @@ |
| 21 | 21 | <tbody> |
| 22 | 22 | {section name=feed loop=$feedlist} |
| 23 | 23 | <tr> |
| 24 | - <td>{$feedlist[feed].title}</td> | |
| 24 | + <td>{$feedlist[feed].title|sanitize}</td> | |
| 25 | 25 | <td><a href="{addQS}action=editFeed&feed_id={$feedlist[feed].id}{/addQS}" class="ktAction ktEdit">{i18n}Edit{/i18n}</a></td> |
| 26 | 26 | <td><a href="{addQS}action=deleteFeed&feed_id={$feedlist[feed].id}{/addQS}" class="ktAction ktDelete">{i18n}Delete{/i18n}</a></td> |
| 27 | 27 | </tr> | ... | ... |