From 037af6890fe6fdb84a08d3c86083e847c90ec0ad Mon Sep 17 00:00:00 2001 From: Aleksander Machniak <alec@alec.pl> Date: Tue, 22 Oct 2013 08:17:26 -0400 Subject: [PATCH] Fix vulnerability in handling _session argument of utils/save-prefs (#1489382) --- program/js/tiny_mce/themes/advanced/charmap.htm | 6 +++++- 1 files changed, 5 insertions(+), 1 deletions(-) diff --git a/program/js/tiny_mce/themes/advanced/charmap.htm b/program/js/tiny_mce/themes/advanced/charmap.htm index 2c3b3f2..d4b6bdf 100644 --- a/program/js/tiny_mce/themes/advanced/charmap.htm +++ b/program/js/tiny_mce/themes/advanced/charmap.htm @@ -5,7 +5,7 @@ <script type="text/javascript" src="../../tiny_mce_popup.js"></script> <script type="text/javascript" src="js/charmap.js"></script> </head> -<body id="charmap" style="display:none"> +<body id="charmap" style="display:none" role="application"> <table align="center" border="0" cellspacing="0" cellpadding="2" role="presentation"> <tr> <td colspan="2" class="title" ><label for="charmapView" id="charmap_label">{#advanced_dlg.charmap_title}</label></td> @@ -46,6 +46,10 @@ </table> </td> </tr> + <tr> + <td colspan="2" id="charmap_usage">{#advanced_dlg.charmap_usage}</td> + </tr> + </table> </body> </html> -- Gitblit v1.9.1