Skip to content
Snippets Groups Projects
Commit 37ed78a1 authored by Frank Naegler's avatar Frank Naegler Committed by Oliver Hader
Browse files

[SECURITY] Prevent XSS in EXT:form error message output

Resolves: #88629
Releases: master, 9.5, 8.7
Security-Commit: df38c239aa9c627fb7b6f1c384d45ff0940d98fa
Security-Bulletin: TYPO3-CORE-SA-2019-021
Change-Id: Ib12dc0affe7f15f1869cff57ea09d9999a0d632a
Reviewed-on: https://review.typo3.org/c/Packages/TYPO3.CMS/+/62715


Tested-by: default avatarOliver Hader <oliver.hader@typo3.org>
Reviewed-by: default avatarOliver Hader <oliver.hader@typo3.org>
parent 24e9e17a
Branches
Tags
No related merge requests found
......@@ -10,7 +10,7 @@
<f:if condition="{validationResults.flattenedErrors}">
<span class="error help-block" role="alert">
<f:for each="{validationResults.errors}" as="error">
{formvh:translateElementError(element: element, error: error)}
<f:format.htmlspecialchars>{formvh:translateElementError(element: element, error: error)}</f:format.htmlspecialchars>
<br />
</f:for>
</span>
......
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment