Skip to content

Commit ec7264c

Browse files
committed
securityfix: CP-30: Manage Website – Compose
1 parent 0e999e2 commit ec7264c

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

emailMarketing/emailMarketingManager.py

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -690,6 +690,9 @@ def saveEmailTemplate(self):
690690
replyTo = data['replyTo']
691691
emailMessage = data['emailMessage']
692692

693+
if ACLManager.CheckRegEx('[\w\d\s]+$', name) == 0:
694+
return ACLManager.loadErrorJson()
695+
693696
admin = Administrator.objects.get(pk=userID)
694697
newTemplate = EmailTemplate(owner=admin, name=name.replace(' ', ''), subject=subject, fromName=fromName, fromEmail=fromEmail,
695698
replyTo=replyTo, emailMessage=emailMessage)

0 commit comments

Comments
 (0)