fix: sanitize all-products search before displaying results (#21764)
Signed-off-by: Chinmay D. Pai <chinmaydpai@gmail.com>
This commit is contained in:
parent
c0b4ec52de
commit
49b2b155b6
@ -11,7 +11,7 @@
|
|||||||
<div class="input-group input-group-sm mb-3">
|
<div class="input-group input-group-sm mb-3">
|
||||||
<input type="search" class="form-control" placeholder="{{_('Search')}}"
|
<input type="search" class="form-control" placeholder="{{_('Search')}}"
|
||||||
aria-label="{{_('Product Search')}}" aria-describedby="product-search"
|
aria-label="{{_('Product Search')}}" aria-describedby="product-search"
|
||||||
value="{{ frappe.form_dict.search or '' }}"
|
value="{{ frappe.sanitize_html(frappe.form_dict.search) or '' }}"
|
||||||
>
|
>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
Loading…
Reference in New Issue
Block a user