Skip to content
Snippets Groups Projects
Commit bae29de9 authored by Olav Morken's avatar Olav Morken
Browse files

login-template: Escape variables added to output.

git-svn-id: https://simplesamlphp.googlecode.com/svn/trunk@99 44740490-163a-0410-bde0-09ae8108e29a
parent ebd76b7f
No related branches found
No related tags found
No related merge requests found
......@@ -30,11 +30,11 @@
<td style="padding: .3em;">Username</td>
<td><input type="text" tabindex="1" name="username"
<?php if (isset($data['username'])) {
echo 'value="' . $data['username'] . '"';
echo 'value="' . htmlspecialchars($data['username']) . '"';
} ?> /></td>
<td style="padding: .4em; rowspan="2">
<input type="submit" tabindex="3" value="Login" />
<input type="hidden" name="RelayState" value="<?php echo $data['relaystate']; ?>" />
<input type="hidden" name="RelayState" value="<?php echo htmlspecialchars($data['relaystate']); ?>" />
</td>
</tr>
<tr>
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment