Commit e3b6e7c7f11580b3633967fef64f0234ea1a5da4
1 parent
bf5eae1f
KTS-2178
"cross site scripting" Implemented. Reviewed By: Kevin Fourie git-svn-id: https://kt-dms.svn.sourceforge.net/svnroot/kt-dms/trunk@6993 c91229c3-7414-0410-bfa2-8a42b809f60b
Showing
1 changed file
with
1 additions
and
1 deletions
templates/ktcore/action/checkout_final.smarty
| ... | ... | @@ -3,7 +3,7 @@ |
| 3 | 3 | {$context->oPage->requireJSResource("thirdpartyjs/MochiKit/Iter.js")} |
| 4 | 4 | {$context->oPage->requireJSResource("thirdpartyjs/MochiKit/DOM.js")} |
| 5 | 5 | |
| 6 | -{capture assign=sLocation}action=checkout_final&fDocumentId={$context->oDocument->getId()}&reason={$reason}{/capture} | |
| 6 | +{capture assign=sLocation}action=checkout_final&fDocumentId={$context->oDocument->getId()}&reason={$reason|escape:'url'}{/capture} | |
| 7 | 7 | |
| 8 | 8 | {capture assign=sJavascript} |
| 9 | 9 | function doCheckout () {ldelim} | ... | ... |