Commits

Anonymous committed 2fbf99e

Fixed an HTML injection attack in outputting the title of the page.

  • Participants
  • Parent commits 81705d3

Comments (0)

Files changed (1)

modules/Mail-LMLM/lib/Mail/LMLM/Render/HTML.pm

     my $head_title = shift;
 
     my $body_title = shift;
+
+    $head_title = _htmlize($head_title);
     
     my $o = $self->{'out'};