AC-4804: Security fixes for XSS, possible sql injection on multiple scripts within...
[acontent.git] / docs / themes / default / course_category / index.tmpl.php
index a65e4fc..ba4b5a5 100644 (file)
@@ -17,7 +17,7 @@ include(TR_INCLUDE_PATH.'header.inc.php');
 ?>\r
 \r
 <div class="input-form">\r
-  <form name="add_form" method="post" action="<?php echo $_SERVER['PHP_SELF']; ?>" >\r
+  <form name="add_form" method="post" action="<?php echo AT_print($_SERVER['PHP_SELF'], 'input.form'); ?>" >\r
   <fieldset class="group_form"><legend class="group_form"><?php echo _AT("add_course_category"); ?></legend>\r
     <table class="form-data" align="left">\r
     <tr align="left">\r