From 13143fbad9d1cb6e00d4e19ffd6757cb1fc26306 Mon Sep 17 00:00:00 2001 From: Chris Hallberg <crhallberg@gmail.com> Date: Thu, 26 May 2016 13:01:59 -0400 Subject: [PATCH] Escape hiddenId. --- .../templates/RecordDriver/SolrDefault/list-entry.phtml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/themes/bootstrap3/templates/RecordDriver/SolrDefault/list-entry.phtml b/themes/bootstrap3/templates/RecordDriver/SolrDefault/list-entry.phtml index 6596ef3cb9a..9b75791676d 100644 --- a/themes/bootstrap3/templates/RecordDriver/SolrDefault/list-entry.phtml +++ b/themes/bootstrap3/templates/RecordDriver/SolrDefault/list-entry.phtml @@ -18,7 +18,7 @@ <div class="col-xs-1 left"> <? endif ?> <label class="pull-left flip"><?=$this->record($this->driver)->getCheckbox() ?></label> - <input type="hidden" value="<?=$id ?>" class="hiddenId"/> + <input type="hidden" value="<?=$this->escapeHtmlAttr($id) ?>" class="hiddenId"/> <? if ($cover): ?> <?=$cover ?> </div> -- GitLab