From 36b66f4c23f64501426a2c0a4b92db5e98763f8c Mon Sep 17 00:00:00 2001 From: im-mi Date: Mon, 29 Aug 2016 00:26:55 -0400 Subject: [PATCH 1/2] html_escape data-tags for tags that contain single quotes --- core/basethemelet.class.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/core/basethemelet.class.php b/core/basethemelet.class.php index de23c99b..71ce4288 100644 --- a/core/basethemelet.class.php +++ b/core/basethemelet.class.php @@ -54,7 +54,7 @@ class BaseThemelet { $h_view_link = make_link('post/view/'.$i_id); $h_thumb_link = $image->get_thumb_link(); $h_tip = html_escape($image->get_tooltip()); - $h_tags = strtolower($image->get_tag_list()); + $h_tags = html_escape(strtolower($image->get_tag_list())); $extArr = array_flip(array('swf', 'svg', 'mp3')); //List of thumbless filetypes if(!isset($extArr[$image->ext])){ From 84b4ac38935ef184996a8768a9bbc451e3261ddd Mon Sep 17 00:00:00 2001 From: im-mi Date: Mon, 29 Aug 2016 01:07:44 -0400 Subject: [PATCH 2/2] html_escape tag info link --- ext/tag_list/theme.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/ext/tag_list/theme.php b/ext/tag_list/theme.php index db9bf4af..0e97abb5 100644 --- a/ext/tag_list/theme.php +++ b/ext/tag_list/theme.php @@ -216,7 +216,7 @@ class TagListTheme extends Themelet { $count = $row['calc_count']; // if($n++) $display_html .= "\n
"; if(!is_null($config->get_string('info_link'))) { - $link = str_replace('$tag', $tag, $config->get_string('info_link')); + $link = html_escape(str_replace('$tag', $tag, $config->get_string('info_link'))); $display_html .= ' ?'; } $link = $this->tag_link($row['tag']);