LP#1822630: sanitize user input before display on browse results
authorJeff Davis <jdavis@sitka.bclibraries.ca>
Mon, 1 Apr 2019 17:00:59 +0000 (10:00 -0700)
committerGalen Charlton <gmc@equinoxinitiative.org>
Thu, 19 Sep 2019 19:31:25 +0000 (15:31 -0400)
Signed-off-by: Jeff Davis <jdavis@sitka.bclibraries.ca>
Signed-off-by: Chris Sharp <csharp@georgialibraries.org>
Signed-off-by: Jason Stephenson <jason@sigio.com>
Signed-off-by: Galen Charlton <gmc@equinoxinitiative.org>

Open-ILS/src/templates/opac/browse.tt2

index 21c3e65..97a8c0c 100644 (file)
@@ -46,7 +46,7 @@
                 <div id="browse-controls" class='searchbar'>
                     <form method="get" onsubmit="$('browse-submit-spinner').className = ''; return true">
                         <input type="hidden" name="blimit"
-                            value="[% blimit %]" />
+                            value="[% blimit | html %]" />
 
                         [% control_qtype = INCLUDE "opac/parts/qtype_selector.tt2"
                             id="browse-search-class" browse_only=1 plural=1 %]