We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 823ea74 commit 586cca3Copy full SHA for 586cca3
app/View/Layouts/default.ctp
@@ -101,9 +101,9 @@
101
var baseurl = '<?php echo $baseurl; ?>';
102
var here = '<?php
103
if (substr($this->params['action'], 0, 6) === 'admin_') {
104
- echo $baseurl . '/admin/' . $this->params['controller'] . '/' . substr($this->params['action'], 6);
+ echo $baseurl . '/admin/' . h($this->params['controller']) . '/' . h(substr($this->params['action'], 6));
105
} else {
106
- echo $baseurl . '/' . $this->params['controller'] . '/' . $this->params['action'];
+ echo $baseurl . '/' . h($this->params['controller']) . '/' . h($this->params['action']);
107
}
108
?>';
109
$(document).ready(function(){
0 commit comments