v1.1.5-cvs
----------
+[mms] SECURITY: XSS - Make sure mailbox name displayed on mailbox page is
+ properly encoded (Bug #9240).
[jan] Fix notices with certain output buffer configurations
(Valentin.Vidic@CARNet.hr, Bug #7851).
[mms] Turn DNS prefetching off when displaying untrusted message content
case 'horde.message':
case 'horde.success':
case 'horde.warning':
- this.Growler.growl(m.message, {
+ this.Growler.growl(m.message.escapeHTML(), {
className: m.type.replace('.', '-'),
life: (m.type == 'horde.error' ? 12 : 8),
log: 1
case 'imp.reply':
case 'imp.forward':
case 'imp.redirect':
- this.Growler.growl(m.message, {
+ this.Growler.growl(m.message.escapeHTML(), {
className: m.type.replace('.', '-'),
life: 8
});