[SECURITY] Missing escaping in scheduler
authorGeorg Ringer <mail@ringerge.org>
Wed, 28 Mar 2012 11:56:31 +0000 (13:56 +0200)
committerOliver Hader <oliver@typo3.org>
Wed, 28 Mar 2012 11:56:37 +0000 (13:56 +0200)
commit064005b20296a2e919b284aed23d603b22d72b63
tree67131a600f79266a34b4fe4782df5006eed5780a
parentb9e19bda10be24f26c09c779b2835973acc03a6f
[SECURITY] Missing escaping in scheduler

A proper escaping is missing for field "frequency"
Sanitize submitted uid

Change-Id: I882d167f55b813f7f20beba48ee09792acec4935
Fixes: #24474
Releases: 6.0, 4.7, 4.6, 4.5, 4.4
Security-Commit: 68a9d5c2de0b6d466373cdde07fef03161bfa2de
Security-Bulletin: TYPO3-CORE-SA-2012-001
Reviewed-on: http://review.typo3.org/10034
Reviewed-by: Oliver Hader
Tested-by: Oliver Hader
typo3/sysext/scheduler/class.tx_scheduler_module.php