Skip to content

Commit

Permalink
XWIKI-20341: Sanitize template URLs
Browse files Browse the repository at this point in the history
  • Loading branch information
surli committed Feb 2, 2023
1 parent 540c01c commit e80d22d
Showing 1 changed file with 3 additions and 3 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -333,11 +333,11 @@
</div>
<input type="submit" class="btn btn-primary" value="$services.localization.render('yes')"/>
#if("$!{request.xredirect}" != '')
#set($cancelUrl = "$request.xredirect")
#getSanitizedURLAttributeValue('a','href',$request.xredirect,$doc.getURL(),$cancelUrl)
#else
#set($cancelUrl = $doc.getURL())
#set($cancelUrl = $escapetool.xml($doc.getURL()))
#end
<a class="btn btn-default" href="$!{escapetool.xml(${cancelUrl})}">$services.localization.render('no')</a>
<a class="btn btn-default" href="$cancelUrl">$services.localization.render('no')</a>
</form>
#xwikimessageboxend()
#end

0 comments on commit e80d22d

Please # to comment.