Projet

Général

Profil

Anomalie #1280 » 0001-Fix-unescaped-variable-in-mailing-template.patch

Guillaume AGNIERAY, 13/09/2019 11:43

Voir les différences:

galette/templates/default/mailing_adherents.tpl
var _val = _this.val();
switch (_val) {
case '{Galette\Core\GaletteMail::SENDER_PREFS}':
_sender_name.val('{$preferences->pref_email_nom}');
_sender_name.val('{$preferences->pref_email_nom|escape:"js"}');
_sender_address.val('{$preferences->pref_email|escape:"js"}');
break;
case '{Galette\Core\GaletteMail::SENDER_CURRENT}':
_sender_name.val('{$sender_current['name']}');
_sender_name.val('{$sender_current['name']|escape:"js"}');
_sender_address.val('{$sender_current['email']|escape:"js"}');
break;
case '{Galette\Core\GaletteMail::SENDER_OTHER}':
(1-1/3)