From 1b2c2666493f6160fe4742370f62d6e1dc73fa84 Mon Sep 17 00:00:00 2001 From: Nathan Kinkade Date: Fri, 14 Mar 2014 23:56:30 +0000 Subject: Fixed some escaping problems which were perhaps insecure and definitely causing validation problems. --- templates/food_search.tpl | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/templates/food_search.tpl b/templates/food_search.tpl index e265360..7d8b26d 100644 --- a/templates/food_search.tpl +++ b/templates/food_search.tpl @@ -12,7 +12,7 @@ {if isset($searchResults)}
The following items matched your search. - Select one, or refine your search. + Select one, or refine your search.
{if $sortType == "Category"} @@ -21,11 +21,11 @@ {foreach from=$foodCat.searchResults item=searchResult}
{if $category == "userFood"} - {$searchResult.foodDesc} + {$searchResult.foodDesc|escape:"html"} {elseif $category == "userMeal"} - {$searchResult.foodDesc} + {$searchResult.foodDesc|escape:"html"} {else} - {$searchResult.foodDesc} + {$searchResult.foodDesc|escape:"html"} {/if}
{/foreach} @@ -34,11 +34,11 @@ {foreach from=$searchResults item=searchResult}
{if $searchResult.category == "userFood"} - {$searchResult.foodDesc|escape:"html"} + {$searchResult.foodDesc|escape:"html"} {elseif $searchResult.category == "userMeal"} - {$searchResult.foodDesc|escape:"html"} + {$searchResult.foodDesc|escape:"html"} {else} - {$searchResult.foodDesc|escape:"html"} + {$searchResult.foodDesc|escape:"html"} {/if}
{/foreach} -- cgit v1.2.3