]> wagnertech.de Git - kivitendo-erp.git/commitdiff
Attribut "name" HTML-escapen.
authorMoritz Bunkus <m.bunkus@linet-services.de>
Fri, 26 Sep 2008 08:28:48 +0000 (08:28 +0000)
committerMoritz Bunkus <m.bunkus@linet-services.de>
Fri, 26 Sep 2008 08:28:48 +0000 (08:28 +0000)
templates/webpages/ct/form_header_de.html
templates/webpages/ct/form_header_master.html

index 6102f12735a0c72a5e03dc4a3b7222015aa523a3..f93de8ca7a457558acb08df704d7506627aef859 100644 (file)
@@ -47,7 +47,7 @@
 
      <tr>
       <th align="right" nowrap>Firmenname</th>
-      <td><input name="name" size="35" maxlength="75" value="[% name %]"></td>
+      <td><input name="name" size="35" maxlength="75" value="[% HTML.escape(name) %]"></td>
      </tr>
 
      <tr>
index 9c81380e19e339c9c6f8ff67392fa79089014033..ef278a3d5bda24c8babce30fce366e8003b4a420 100644 (file)
@@ -47,7 +47,7 @@
 
      <tr>
       <th align="right" nowrap><translate>Company Name</translate></th>
-      <td><input name="name" size="35" maxlength="75" value="[% name %]"></td>
+      <td><input name="name" size="35" maxlength="75" value="[% HTML.escape(name) %]"></td>
      </tr>
 
      <tr>