Corrected issues with unsanitized output that would allow someone with administrative access to insert malicious javascript. Also added tokens on certain urls that could have been spoofed by someone with administrative access.
Corrected issues with unsanitized output that would allow someone with administrative access to insert malicious javascript. Also added tokens on certain urls that could have been spoofed by someone with administrative access.