[SECURITY] XSS in validateForm
authorMarkus Bucher <markusbucher@gmx.de>
Wed, 15 Aug 2012 10:19:03 +0000 (12:19 +0200)
committerOliver Hader <oliver.hader@typo3.org>
Wed, 15 Aug 2012 10:19:07 +0000 (12:19 +0200)
commit1eaebd3892e2179d6608e589a9e64d338e0cb8bc
tree727862e71c6758a99b5119174f9cd16e92ab3122
parent9b2b8fb90d2f06ec59661250d19195c51e2a767c
[SECURITY] XSS in validateForm

Properly quote the form name and field list
for the JavaScript validation

Fixes: #25052
Releases: 6.0, 4.7, 4.6, 4.5

Change-Id: I98bfef92b5595ab343a49e1cba1d8b2563d1d8aa
Security-Commit: d832f7be6bad577ba0be08a7382b421a433ee07f
Security-Bulletin: TYPO3-CORE-SA-2012-004
Reviewed-on: http://review.typo3.org/13752
Reviewed-by: Oliver Hader
Tested-by: Oliver Hader
typo3/sysext/cms/tslib/content/class.tslib_content_form.php