Commit 54b7d082 authored by Tres Seaver's avatar Tres Seaver Committed by GitHub

Merge pull request #87 from zopefoundation/apply-plonehotfix-20170717-master

Apply plonehotfix 20170717 [master]
parents d690799f 812c4176
......@@ -11,6 +11,9 @@ https://zope.readthedocs.io/en/2.13/CHANGES.html
Bugs Fixed
++++++++++
- Fixed reflective XSS in findResult.
This applies PloneHotfix20170117. [maurits]
- Patch zope.interface to remove docstrings and avoid publishing.
From Products.PloneHotfix20161129. [maurits]
......
......@@ -124,7 +124,7 @@ your search terms below.
</div>
</TD>
<TD ALIGN="LEFT" VALIGN="TOP">
<INPUT TYPE="TEXT" NAME="obj_ids:tokens" SIZE="30" VALUE="<dtml-var "' '.join(obj_ids or [])">">
<INPUT TYPE="TEXT" NAME="obj_ids:tokens" SIZE="30" VALUE="<dtml-var "' '.join(obj_ids or [])" html_quote>">
</TD>
</TR>
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment