Commit debe7079 authored by Hanno Schlichting's avatar Hanno Schlichting Committed by GitHub

Merge pull request #68 from zopefoundation/apply-plone-hotfix-20160830-master

Quote variable in manage_tabs to avoid XSS [master]
parents 84272f2a 8aa8b081
...@@ -11,6 +11,9 @@ https://zope.readthedocs.io/en/2.13/CHANGES.html ...@@ -11,6 +11,9 @@ https://zope.readthedocs.io/en/2.13/CHANGES.html
Bugs Fixed Bugs Fixed
++++++++++ ++++++++++
- Quote variable in manage_tabs to avoid XSS.
From Products.PloneHotfix20160830. [maurits]
- Remove more HelpSys references. - Remove more HelpSys references.
Features Added Features Added
......
...@@ -38,8 +38,8 @@ ...@@ -38,8 +38,8 @@
<dtml-in manage_options mapping> <dtml-in manage_options mapping>
<dtml-let s_item=sequence-item s_index=sequence-index> <dtml-let s_item=sequence-item s_index=sequence-index>
<dtml-if "s_index==a_"> <dtml-if "s_index==a_">
<td bgcolor="#ffffff" valign="bottom" class="tab-small" <td bgcolor="#ffffff" valign="bottom" class="tab-small"
align="center"><font face="Verdana, Arial, Helvetica" align="center"><font face="Verdana, Arial, Helvetica"
size="1" color="#000000">&nbsp;<a <dtml-if "s_item.get('action')" size="1" color="#000000">&nbsp;<a <dtml-if "s_item.get('action')"
>href="&dtml-action;"<dtml-else >href="&dtml-action;"<dtml-else
>href="<dtml-var "REQUEST.URL1" html_quote>"</dtml-if >href="<dtml-var "REQUEST.URL1" html_quote>"</dtml-if
...@@ -47,8 +47,8 @@ ...@@ -47,8 +47,8 @@
>><span style="color: #000000;"><strong><dtml-var "s_item['label']" >><span style="color: #000000;"><strong><dtml-var "s_item['label']"
></strong></span></a>&nbsp;</font></td> ></strong></span></a>&nbsp;</font></td>
<dtml-else> <dtml-else>
<td bgcolor="#efefef" valign="bottom" class="tab-small" <td bgcolor="#efefef" valign="bottom" class="tab-small"
align="center"><font face="Verdana, Arial, Helvetica" align="center"><font face="Verdana, Arial, Helvetica"
size="1" color="#000000">&nbsp;<a <dtml-if "s_item.get('action')" size="1" color="#000000">&nbsp;<a <dtml-if "s_item.get('action')"
>href="&dtml-action;"<dtml-else >href="&dtml-action;"<dtml-else
>href="<dtml-var "REQUEST.URL1" html_quote>"</dtml-if >href="<dtml-var "REQUEST.URL1" html_quote>"</dtml-if
...@@ -82,7 +82,7 @@ ...@@ -82,7 +82,7 @@
&dtml-meta_type; &dtml-meta_type;
<dtml-else> <dtml-else>
Object Object
</dtml-if> </dtml-if>
at <dtml-var expr="tabs_path_default(REQUEST)"> at <dtml-var expr="tabs_path_default(REQUEST)">
</strong> </strong>
<dtml-if wl_isLocked> <dtml-if wl_isLocked>
...@@ -97,7 +97,7 @@ ...@@ -97,7 +97,7 @@
<dtml-if manage_tabs_message> <dtml-if manage_tabs_message>
<div class="system-msg"> <div class="system-msg">
<dtml-var manage_tabs_message newline_to_br> <dtml-var manage_tabs_message newline_to_br html_quote>
(<dtml-var ZopeTime fmt="%Y-%m-%d %H:%M">) (<dtml-var ZopeTime fmt="%Y-%m-%d %H:%M">)
</div> </div>
</dtml-if> </dtml-if>
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment