Skip to content

Commit 13875a6

Browse files
committed
XWIKI-20672: Sanitize template URLs
1 parent 02f1b50 commit 13875a6

File tree

1 file changed

+2
-2
lines changed
  • xwiki-platform-core/xwiki-platform-flamingo/xwiki-platform-flamingo-skin/xwiki-platform-flamingo-skin-resources/src/main/resources/flamingo

1 file changed

+2
-2
lines changed

xwiki-platform-core/xwiki-platform-flamingo/xwiki-platform-flamingo-skin/xwiki-platform-flamingo-skin-resources/src/main/resources/flamingo/delete.vm

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -307,9 +307,9 @@
307307
</div>
308308
<button class="btn btn-danger confirm">$escapetool.xml($services.localization.render('delete'))</button>
309309
#if("$!{request.xredirect}" != '')
310-
#set($cancelUrl = "$request.xredirect")
310+
#getSanitizedURLAttributeValue('a','href',$request.xredirect,$doc.getURL(),$cancelUrl)
311311
#else
312-
#set($cancelUrl = $doc.getURL())
312+
#set($cancelUrl = $escapetool.xml($doc.getURL()))
313313
#end
314314
<a class="btn btn-default cancel" href="$!{escapetool.xml(${cancelUrl})}">$escapetool.xml($services.localization.render('cancel'))</a>
315315
#end

0 commit comments

Comments
 (0)