Skip to content

Commit fe17868

Browse files
Merge pull request #2263 from magento-chaika/MAGETWO-70939
Fixed issues: - MAGETWO-70939: Reflected XSS in admin Reports
2 parents c5f460e + bff051c commit fe17868

File tree

1 file changed

+2
-2
lines changed
  • app/code/Magento/Reports/view/adminhtml/templates

1 file changed

+2
-2
lines changed

app/code/Magento/Reports/view/adminhtml/templates/grid.phtml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ $numColumns = sizeof($block->getColumns());
3131
type="text"
3232
id="<?= /* @escapeNotVerified */ $block->getSuffixId('period_date_from') ?>"
3333
name="report_from"
34-
value="<?= /* @escapeNotVerified */ $block->getFilter('report_from') ?>">
34+
value="<?= $block->escapeHtml($block->getFilter('report_from')) ?>">
3535
<span id="<?= /* @escapeNotVerified */ $block->getSuffixId('period_date_from_advice') ?>"></span>
3636
</span>
3737

@@ -44,7 +44,7 @@ $numColumns = sizeof($block->getColumns());
4444
type="text"
4545
id="<?= /* @escapeNotVerified */ $block->getSuffixId('period_date_to') ?>"
4646
name="report_to"
47-
value="<?= /* @escapeNotVerified */ $block->getFilter('report_to') ?>"/>
47+
value="<?= $block->escapeHtml($block->getFilter('report_to')) ?>"/>
4848
<span id="<?= /* @escapeNotVerified */ $block->getSuffixId('period_date_to_advice') ?>"></span>
4949
</span>
5050

0 commit comments

Comments
 (0)