[SECURITY] XSS in search results 72/45272/2
authorWouter Wolters <typo3@wouterwolters.nl>
Tue, 15 Dec 2015 10:35:34 +0000 (11:35 +0100)
committerOliver Hader <oliver.hader@typo3.org>
Tue, 15 Dec 2015 10:35:40 +0000 (11:35 +0100)
commit7e4bdf48988191043a65880c72190c4130c1f0e0
tree1b7efb2e17545adde3dc3031371597b48d3a9e15
parentb341d8491b82c0dc59dd03500cfe88797d618e3d
[SECURITY] XSS in search results

Page titles are not escaped in getPathFromPageId

Resolves: #23155
Releases: 6.2
Security-Commit: 9f2f01429e4cfd9f705b345a8b3c53dfd0bac63d
Security-Bulletins: TYPO3-CORE-SA-2015-010, 011, 012, 013, 014, 015
Change-Id: I65f106e1b504bf9ac45f869ae97582f0cb24f52a
Reviewed-on: https://review.typo3.org/45272
Reviewed-by: Oliver Hader <oliver.hader@typo3.org>
Tested-by: Oliver Hader <oliver.hader@typo3.org>
typo3/sysext/indexed_search/Classes/Controller/SearchFormController.php