Merge pull request #2737 from Icinga/bugfix/searchfield-escaping-12330

FilterEditor: escape values correctly
This commit is contained in:
Eric Lippmann 2017-02-10 09:13:42 +01:00
commit 9d47d651d9

View File

@ -521,7 +521,7 @@ class FilterEditor extends AbstractWidget
return sprintf( return sprintf(
'<input type="text" name="%s" value="%s" />', '<input type="text" name="%s" value="%s" />',
$this->elementId('value', $filter), $this->elementId('value', $filter),
$value $this->view()->escape($value)
); );
} }