Fix a form injection problem with the EMS. Addresses bug #11773.

This commit is contained in:
Colin Kuskie 2010-10-11 13:11:56 -07:00
parent c50688f987
commit 106fcaedf7
2 changed files with 5 additions and 2 deletions

View file

@ -2,6 +2,7 @@
- fixed #11903: Unnecessary debug in Thingy
- fixed #11908: Inbox messages linger after deleting a user
- fixed #11909: Wrong message count in the inbox
- fixed #11773: Form injection in the EMS event ordering code.
7.10.2
- fixed #11884: Editing Templates impossible / Code editor not loaded

View file

@ -2456,7 +2456,8 @@ Method to move an event down one position in display order
sub www_moveEventMetaFieldDown {
my $self = shift;
return $self->session->privilege->insufficient unless ($self->canEdit);
$self->moveCollateralDown('EMSEventMetaField', 'fieldId', $self->session->form->get("fieldId"));
my $fieldId = $self->session->form->get("fieldId");
$self->moveCollateralDown('EMSEventMetaField', 'fieldId', $fieldId);
return $self->www_manageEventMetaFields;
}
@ -2471,7 +2472,8 @@ Method to move an event metdata field up one position in display order
sub www_moveEventMetaFieldUp {
my $self = shift;
return $self->session->privilege->insufficient unless ($self->canEdit);
$self->moveCollateralUp('EMSEventMetaField', 'fieldId', $self->session->form->get("fieldId"));
my $fieldId = $self->session->form->get("fieldId");
$self->moveCollateralUp('EMSEventMetaField', 'fieldId', $fieldId);
return $self->www_manageEventMetaFields;
}