Skip to content

Commit

Permalink
Fixed issue #11818: Non-sanitized output in massive actions for quest…
Browse files Browse the repository at this point in the history
…ion list
  • Loading branch information
c-schmitz committed Oct 20, 2016
1 parent af5ab28 commit 5443235
Show file tree
Hide file tree
Showing 3 changed files with 3 additions and 3 deletions.
Expand Up @@ -9,7 +9,7 @@
<div class="col-sm-8">
<input type="text" class="form-control custom-data attributes-to-update" id="cssclass" name="cssclass" value="">
</div>
<input type="hidden" name="sid" value="<?php echo $_GET['surveyid']; ?>" class="custom-data"/>
<input type="hidden" name="sid" value="<?php echo (int) Yii::app()->request->getParam('surveyid',0); ?>" class="custom-data"/>
<input type="hidden" name="aValidQuestionTypes" value="15ABCDEFGHIKLMNOPQRSTUWXYZ!:;|*" class="custom-data"/>
</div>
</form>
Expand Down
Expand Up @@ -9,6 +9,6 @@
<div class="col-sm-8">
<?php $this->widget('yiiwheels.widgets.switch.WhSwitch', array('name' => 'other', 'value'=> '', 'htmlOptions'=>array('class'=>'custom-data bootstrap-switch-boolean', 'data-gridid'=>'question-grid'), 'onLabel'=>gT('On'),'offLabel'=>gT('Off')));?>
</div>
<input type="hidden" name="sid" value="<?php echo $_GET['surveyid']; ?>" class="custom-data"/>
<input type="hidden" name="sid" value="<?php echo (int) Yii::app()->request->getParam('surveyid',0); ?>" class="custom-data"/>
</div>
</form>
Expand Up @@ -56,7 +56,7 @@
</div>
</div>

<input type="hidden" name="sid" value="<?php echo $_GET['surveyid']; ?>" class="custom-data"/>
<input type="hidden" name="sid" value="<?php echo (int) Yii::app()->request->getParam('surveyid',0); ?>" class="custom-data"/>
<input type="hidden" name="aValidQuestionTypes" value="15ABCDEFGHIKLMNOPQRSTUWXYZ!:;|*" class="custom-data"/>
</form>
<br/><br/>

0 comments on commit 5443235

Please sign in to comment.