CC-4897: XSS exploit on library page

This commit is contained in:
denise 2013-02-04 11:06:46 -05:00
parent 7238790c41
commit 1f0b9fa5dc
2 changed files with 3 additions and 3 deletions

View file

@ -438,7 +438,7 @@ class LibraryController extends Zend_Controller_Action
$formValues = $this->_getParam('data', null);
$formdata = array();
foreach ($formValues as $val) {
$formdata[$val["name"]] = htmlspecialchars($val["value"]);
$formdata[$val["name"]] = $val["value"];
}
$file->setDbColMetadata($formdata);