From 98332f1483dfb97cab1a9ab473a091d36f4474b6 Mon Sep 17 00:00:00 2001 From: slawkens Date: Mon, 27 Nov 2023 20:28:43 +0100 Subject: [PATCH] Fix XSS in bugtracker.php --- system/pages/bugtracker.php | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/system/pages/bugtracker.php b/system/pages/bugtracker.php index 790941cb..3c8154e3 100644 --- a/system/pages/bugtracker.php +++ b/system/pages/bugtracker.php @@ -193,9 +193,9 @@ $showed = $post = $reply = false; $value = '[CLOSED]'; echo ''; - echo ''; + echo ''; echo ''; - echo ''; + echo ''; echo '
Bug Tracker
Subject'.$tags[$bug[2]['tag']].' '.$bug[2]['subject'].' '.$value.'
Subject'.$tags[$bug[2]['tag']].' '.escapeHtml($bug[2]['subject']).' '.$value.'
Description
'.nl2br($bug[2]['text']).'
'.nl2br(escapeHtml($bug[2]['text'])).'
'; $answers = Bugtracker::where('account', $account_logged->getId())->where('id', $id)->where('type', 2)->orderBy('reply')->get()->toArray(); @@ -294,7 +294,7 @@ $showed = $post = $reply = false; $bgcolor = $light; } - echo ''.$tags[$report['tag']].' '.$report['subject'].''.$value.''; + echo ''.$tags[$report['tag']].' '.escapeHtml($report['subject']).''.$value.''; $showed=true; }