Skip to content

Commit 61df064

Browse files
maxmimaxmi
authored andcommitted
XSS Ticket Subject Fix
1 parent 84828f2 commit 61df064

File tree

1 file changed

+1
-1
lines changed
  • src/app/code/community/Zendesk/Zendesk/Helper

1 file changed

+1
-1
lines changed

src/app/code/community/Zendesk/Zendesk/Helper/Data.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -281,7 +281,7 @@ public function getTicketUrl($row, $link = false)
281281

282282
$subject = $row['subject'] ? $row['subject'] : $this->__('No Subject');
283283

284-
return '<a href="' . $url . '" target="_blank">' . $subject. '</a>';
284+
return '<a href="' . $url . '" target="_blank">' . Mage::helper('core')->escapeHtml($subject) . '</a>';
285285
}
286286

287287
public function getStatusMap()

0 commit comments

Comments
 (0)