Project

General

Profile

« Previous | Next » 

Revision 17b38a7c

Added by Tomer Brisker almost 8 years ago

Fixes #16020 - Prevent reflective XSS on form validation

Error messages for various form fields were not properly escaped to
prevent HTML from being insert into them. This caused a possible
reflective XSS in smart class parameter/varaible default value
validations.

(cherry picked from commit cf0ce6d763014a0d637e402dc2266554b97beaa7)

  • added
  • modified
  • copied
  • renamed
  • deleted