From 9a4a11861a9f5a88c41f43751a40247983ac6416 Mon Sep 17 00:00:00 2001 From: Johannes Meyer Date: Wed, 11 Jan 2023 15:30:03 +0100 Subject: [PATCH] Fix some reflected XSS bugs fixes #4979 (cherry picked from commit e542982de06be6b7bcab07be4f3a4423e84b8d7a) --- .../views/scripts/form/reorder-authbackend.phtml | 12 +++++++++++- .../scripts/form/reorder-command-transports.phtml | 10 +++++----- .../views/scripts/form/setup-modules.phtml | 10 +++++----- .../views/scripts/form/setup-requirements.phtml | 10 +++++----- .../views/scripts/form/setup-summary.phtml | 10 +++++----- 5 files changed, 31 insertions(+), 21 deletions(-) diff --git a/application/views/scripts/form/reorder-authbackend.phtml b/application/views/scripts/form/reorder-authbackend.phtml index 08a2431d1..34b10b323 100644 --- a/application/views/scripts/form/reorder-authbackend.phtml +++ b/application/views/scripts/form/reorder-authbackend.phtml @@ -1,4 +1,14 @@ -
+ diff --git a/modules/monitoring/application/views/scripts/form/reorder-command-transports.phtml b/modules/monitoring/application/views/scripts/form/reorder-command-transports.phtml index 49fc8504e..2f81610fa 100644 --- a/modules/monitoring/application/views/scripts/form/reorder-command-transports.phtml +++ b/modules/monitoring/application/views/scripts/form/reorder-command-transports.phtml @@ -3,15 +3,15 @@ /** @var \Icinga\Module\Monitoring\Forms\Config\TransportReorderForm $form */ ?>
translate('Backend') ?>
diff --git a/modules/setup/application/views/scripts/form/setup-modules.phtml b/modules/setup/application/views/scripts/form/setup-modules.phtml index 51a8c2a51..e57c7dcef 100644 --- a/modules/setup/application/views/scripts/form/setup-modules.phtml +++ b/modules/setup/application/views/scripts/form/setup-modules.phtml @@ -4,11 +4,11 @@ use Icinga\Web\Wizard; ?> diff --git a/modules/setup/application/views/scripts/form/setup-requirements.phtml b/modules/setup/application/views/scripts/form/setup-requirements.phtml index ac1ef7b5d..544f284c6 100644 --- a/modules/setup/application/views/scripts/form/setup-requirements.phtml +++ b/modules/setup/application/views/scripts/form/setup-requirements.phtml @@ -14,11 +14,11 @@ if (! $form->getWizard()->getRequirements()->fulfilled()) { getRequirements(); ?> getElement($form->getTokenElementName()); ?> diff --git a/modules/setup/application/views/scripts/form/setup-summary.phtml b/modules/setup/application/views/scripts/form/setup-summary.phtml index bcd259288..3ad02652e 100644 --- a/modules/setup/application/views/scripts/form/setup-summary.phtml +++ b/modules/setup/application/views/scripts/form/setup-summary.phtml @@ -26,11 +26,11 @@ $form->getElement(Wizard::BTN_NEXT)->setAttrib(