[SECURITY] XSS in validateForm
authorMarkus Bucher <markusbucher@gmx.de>
Wed, 15 Aug 2012 10:17:55 +0000 (12:17 +0200)
committerOliver Hader <oliver.hader@typo3.org>
Wed, 15 Aug 2012 10:17:58 +0000 (12:17 +0200)
commit605d05f0c8e9dae4cf88f9a2efc912cbc8fbeef7
treebf87bc5aa5720cefe89e77444166744c0e4e7c20
parent6840097bdadcfd7fb8ad360f70752023fe0f834b
[SECURITY] XSS in validateForm

Properly quote the form name and field list
for the JavaScript validation

Fixes: #25052
Releases: 6.0, 4.7, 4.6, 4.5

Change-Id: I01527117c20e25963951502c2277b853f683fe04
Security-Commit: 20a6486d3027f474fb2352668cdb0fbee5f251f3
Security-Bulletin: TYPO3-CORE-SA-2012-004
Reviewed-on: http://review.typo3.org/13742
Reviewed-by: Oliver Hader
Tested-by: Oliver Hader
typo3/sysext/cms/tslib/content/class.tslib_content_form.php