BUG 10702 Nombres de las tareas no soportan Html tags SOLVED
- Missing validation for html entities - Add validation for html entities
This commit is contained in:
@@ -252,7 +252,7 @@ var saveTaskData = function(oForm, iForm, iType)
|
||||
var res = rpc.xmlhttp.responseText.parseJSON();
|
||||
|
||||
if (oTaskData.TAS_TITLE) {
|
||||
Pm.data.db.task[getField("INDEX").value].label = Pm.data.db.task[getField("INDEX").value].object.elements.label.innerHTML = oTaskData.TAS_TITLE.replace(re2, "&");
|
||||
Pm.data.db.task[getField("INDEX").value].label = Pm.data.db.task[getField("INDEX").value].object.elements.label.innerHTML = htmlentities(oTaskData.TAS_TITLE, 'ENT_QUOTES');
|
||||
}
|
||||
|
||||
if (oTaskData.TAS_START) {
|
||||
|
||||
Reference in New Issue
Block a user