Fixed a potential XSS vulnerability.

SVN:2.1.1[3663]
This commit is contained in:
Denis Flaven
2015-07-30 09:07:47 +00:00
parent 0d14a20e1b
commit fd21ae262b

View File

@@ -312,7 +312,7 @@ abstract class Dashboard
public function Render($oPage, $bEditMode = false, $aExtraParams = array())
{
$oPage->add('<h1>'.Dict::S($this->sTitle).'</h1>');
$oPage->add('<h1>'.htmlentities(Dict::S($this->sTitle), ENT_QUOTES, 'UTF-8', false).'</h1>');
$oLayout = new $this->sLayoutClass;
$oLayout->Render($oPage, $this->aCells, $bEditMode, $aExtraParams);
if (!$bEditMode)