BUG 9621 Persistent XSS and AJAX Vulnerabilities, Multiple SOLVED

- It was noticed that no was validated these entry.
- Was validated with htmlentities for both cases.
This commit is contained in:
Marco Antonio Nina
2012-08-29 15:34:57 -04:00
parent 090e5016df
commit 13be93d3c1
3 changed files with 3 additions and 3 deletions

View File

@@ -31,7 +31,7 @@ class Main extends Controller
// setting variables for template
$this->setVar('logo_company', $this->getCompanyLogo());
$this->setVar('userfullname', $this->getUserFullName());
$this->setVar('userfullname', htmlentities($this->getUserFullName(), ENT_QUOTES, 'UTF-8') );
$this->setVar('user', isset($_SESSION['USR_USERNAME']) ? $_SESSION['USR_USERNAME'] : '');
$this->setVar('pipe', isset($_SESSION['USR_USERNAME']) ? ' | ' : '');
$this->setVar('rolename', $this->getUserRole());