Permalink
Browse files

fix another XSS

  • Loading branch information...
1 parent f955f6a commit 642e7ce110cb8c320072532c29abe003385d50f5 Georg Ehrke committed Jun 9, 2012
Showing with 3 additions and 0 deletions.
  1. +3 −0 apps/calendar/templates/part.import.php
@@ -8,6 +8,9 @@
<?php
$calendar_options = OC_Calendar_Calendar::allCalendars(OCP\USER::getUser());
$calendar_options[] = array('id'=>'newcal', 'displayname'=>$l->t('create a new calendar'));
+for($i = 0;$i<count($calendar_options);$i++){
+ $calendar_options[$i]['displayname'] = htmlspecialchars($calendar_options[$i]['displayname']);
+}
echo OCP\html_select_options($calendar_options, $calendar_options[0]['id'], array('value'=>'id', 'label'=>'displayname'));
?>
</select>

0 comments on commit 642e7ce

Please sign in to comment.