Merge pull request #576 from im-mi/fix-pool-description-code-injection

Update pool description formatter (code injection vulnerability)
This commit is contained in:
Shish 2016-09-01 11:18:37 +01:00 committed by GitHub
commit 29bdc5da22

View File

@ -154,8 +154,9 @@ class PoolsTheme extends Themelet {
} }
} }
$bb = new BBCode(); $tfe = new TextFormattingEvent($pool['description']);
$page->add_block(new Block(html_escape($pool['title']), $bb->format($pool['description']), "main", 10)); send_event($tfe);
$page->add_block(new Block(html_escape($pool['title']), $tfe->formatted, "main", 10));
} }
} }