From 02aa6ce0a7cd9ef14079a5ee22c175ff9d16ed58 Mon Sep 17 00:00:00 2001 From: David Lawrence Date: Tue, 8 Mar 2016 14:26:33 +0000 Subject: Bug 1252445 - Tracking flags configuration is vulnerable to CSRF and causes persistent XSS --- .../en/default/pages/tracking_flags_admin_edit.html.tmpl | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) (limited to 'extensions/TrackingFlags/template/en/default/pages/tracking_flags_admin_edit.html.tmpl') diff --git a/extensions/TrackingFlags/template/en/default/pages/tracking_flags_admin_edit.html.tmpl b/extensions/TrackingFlags/template/en/default/pages/tracking_flags_admin_edit.html.tmpl index 60406490f..e381c4f1c 100644 --- a/extensions/TrackingFlags/template/en/default/pages/tracking_flags_admin_edit.html.tmpl +++ b/extensions/TrackingFlags/template/en/default/pages/tracking_flags_admin_edit.html.tmpl @@ -30,9 +30,12 @@ var selected_components = [ %]
@@ -50,6 +53,7 @@ var selected_components = [ + [%# name/desc/etc %] -- cgit v1.2.3-24-g4f1b