fixed possible security problem.

This commit is contained in:
Len Kranendonk 2003-02-21 14:03:06 +00:00
parent de1d5834ac
commit 713811353c

View file

@ -358,6 +358,8 @@ sub _createField {
my $name = WebGUI::URL::urlize($data->{name});
my $f = WebGUI::HTMLForm->new( 'noTable' );
$session{form}{$name} =~ s/\^.*?\;//gs ; # remove macro's from user input
SWITCH: for ($data->{type}) {
/^text$/ && do {
$f->text(