Переглянути джерело

푸시서비스관리 취약점 수정

huiwon.seo 4 роки тому
батько
коміт
6b30de2de9
1 змінених файлів з 10 додано та 10 видалено
  1. 10 10
      src/main/webapp/WEB-INF/jsp/push/list.jsp

+ 10 - 10
src/main/webapp/WEB-INF/jsp/push/list.jsp

@@ -317,7 +317,7 @@ function pushDetail( t ){
                     <!-- 의료진 관리 START -->
                     <div class="row">
                         <div class="col-12 col-lg-6">
-                            <h1 class="h3 mb-3">월별 푸시 발송 현황 (${y}년 ${m}월)</h1>
+                            <h1 class="h3 mb-3">월별 푸시 발송 현황 (<c:out value="${y}"/><c:out value="${m}"/>월)</h1>
                         </div>
                         <div class="col-12 col-lg-6  text-right">
                             <nav aria-label="breadcrumb">
@@ -333,7 +333,7 @@ function pushDetail( t ){
                         <div class="col-12">
                             <div class="card">
                                 <form action="?" method="get" id="searchForm">
-                                    <input type="hidden" id="ym" value="${ym}" />
+                                    <input type="hidden" id="ym" value='<c:out value="${ym}"/>' />
                                     <div class="card-body">
                                         <table class="table mobile-table">
                                             <colgroup>
@@ -370,7 +370,7 @@ function pushDetail( t ){
                                                     <div class="row">
                                                         <div class="col-5">
                                                             <div class="form-group mb-xl-0">
-                                                                <input class="form-control date-no-req" type="text" name="startDate" value="${startDate}" onKeyup="inputYMDNumber(this);" autocomplete="off"  placeholder="검색 시작일자">
+                                                                <input class="form-control date-no-req" type="text" name="startDate" value='<c:out value="${startDate}"/>' onKeyup="inputYMDNumber(this);" autocomplete="off"  placeholder="검색 시작일자">
                                                             </div>
                                                         </div>
                                                         <div
@@ -378,7 +378,7 @@ function pushDetail( t ){
                                                             ~</div>
                                                         <div class="col-5">
                                                             <div class="form-group mb-xl-0">
-                                                                <input class="form-control date-no-req" type="text" name="endDate" value="${endDate}" onKeyup="inputYMDNumber(this);" autocomplete="off" placeholder="검색 종료일자">
+                                                                <input class="form-control date-no-req" type="text" name="endDate" value='<c:out value="${endDate}"/>' onKeyup="inputYMDNumber(this);" autocomplete="off" placeholder="검색 종료일자">
                                                             </div>
                                                         </div>
                                                     </div>
@@ -497,12 +497,12 @@ function pushDetail( t ){
                                                         </td>
                                                         <td class="td-push-title text-left">
                                                             <a href="javascript:;" data-toggle="modal" data-target="#defaultModalPrimary_1" onclick="pushDetail( this );"><c:out value="${pl.pushTitle}"/></a>
-                                                            <input type="hidden" class="log-idx" value="${pl.idx}" />
-                                                            <input type="hidden" class="push-idx" value="${pl.pushIdx}" />
-                                                            <input type="hidden" class="center-name" value="${pl.centerName}" />
-                                                            <input type="hidden" class="sender" value="${pl.sender}" />
-                                                            <input type="hidden" class="name" value="${pl.name}" />
-                                                            <input type="hidden" class="push-content" value="${pl.pushContent}" />
+                                                            <input type="hidden" class="log-idx" value='<c:out value="${pl.idx}"/>' />
+                                                            <input type="hidden" class="push-idx" value='<c:out value="${pl.pushIdx}"/>' />
+                                                            <input type="hidden" class="center-name" value='<c:out value="${pl.centerName}"/>' />
+                                                            <input type="hidden" class="sender" value='<c:out value="${pl.sender}"/>' />
+                                                            <input type="hidden" class="name" value='<c:out value="${pl.name}"/>' />
+                                                            <input type="hidden" class="push-content" value='<c:out value="${pl.pushContent}"/>' />
                                                         </td>
                                                         <td class="td-target-type">
                                                             <c:if test="${pl.targetType eq 'A'}">전체 환자</c:if>