Commit d1bfea3b authored by Dave Cridland's avatar Dave Cridland

OF-942 Reflected XSS in MUC room edit form

parent 1a3bf443
......@@ -525,11 +525,11 @@
</tr>
<tr>
<td><fmt:message key="muc.room.edit.form.required_password" />:</td>
<td><input type="password" name="roomconfig_roomsecret" <% if(password != null) { %> value="<%= password %>" <% } %>></td>
<td><input type="password" name="roomconfig_roomsecret" <% if(password != null) { %> value="<%= (password == null ? "" : StringUtils.escapeForXML(password)) %>" <% } %>></td>
</tr>
<tr>
<td><fmt:message key="muc.room.edit.form.confirm_password" />:</td>
<td><input type="password" name="roomconfig_roomsecret2" <% if(confirmPassword != null) { %> value="<%= confirmPassword %>" <% } %>>
<td><input type="password" name="roomconfig_roomsecret2" <% if(confirmPassword != null) { %> value="<%= (confirmPassword == null ? "" : StringUtils.escapeForXML(confirmPassword)) %>" <% } %>>
</td>
</tr>
<tr>
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment