Skip to content

Commit

Permalink
Merge pull request #58 from jmmacdo4/master
Browse files Browse the repository at this point in the history
EMPT-74. Fix XSS vulnerability on the manage privilege page
  • Loading branch information
isears committed Apr 1, 2021
2 parents 702fbfd + 27d8a63 commit 4f85654
Showing 1 changed file with 3 additions and 3 deletions.
6 changes: 3 additions & 3 deletions omod/src/main/webapp/pages/metadata/privileges/privilege.gsp
Original file line number Diff line number Diff line change
Expand Up @@ -71,8 +71,8 @@
initialValue : ui.encodeHtmlContent(privilege.privilege)
])}
<% } else{ %>
<b>${ui.message("general.name")}:</b> ${privilege.privilege}
<input type="hidden" name="privilegeName" value="${privilege.privilege}" />
<b>${ui.message("general.name")}:</b> ${ui.encodeHtmlContent(privilege.privilege)}
<input type="hidden" name="privilegeName" value="${ui.encodeHtmlAttribute(privilege.privilege)}" />
<% } %>
${ui.includeFragment("uicommons", "field/textarea", [
label : ui.message("general.description"),
Expand All @@ -86,4 +86,4 @@
<input type="submit" class="confirm" id="save-button" value="${ui.message("general.save")}"/>
</div>
</fieldset>
</form>
</form>

0 comments on commit 4f85654

Please sign in to comment.