From 83a91ec540072d319dd338abff45f8d5ebf48190 Mon Sep 17 00:00:00 2001 From: slawkens Date: Mon, 27 Nov 2023 20:28:43 +0100 Subject: [PATCH] Fix XSS in bugtracker.php --- system/pages/bugtracker.php | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/system/pages/bugtracker.php b/system/pages/bugtracker.php index ac37becd62..775b09f909 100644 --- a/system/pages/bugtracker.php +++ b/system/pages/bugtracker.php @@ -181,9 +181,9 @@ $value = '[CLOSED]'; echo ''; - echo ''; + echo ''; echo ''; - echo ''; + echo ''; echo '
Bug Tracker
Subject'.$tags[$bug[2]['tag']].' '.$bug[2]['subject'].' '.$value.'
Subject'.$tags[$bug[2]['tag']].' '.escapeHtml($bug[2]['subject']).' '.$value.'
Description
'.nl2br($bug[2]['text']).'
'.nl2br(escapeHtml($bug[2]['text'])).'
'; $answers = $db->query('SELECT * FROM '.$db->tableName('myaac_bugtracker').' where `account` = '.$account_logged->getId().' and `id` = '.$id.' and `type` = 2 order by `reply`'); @@ -274,7 +274,7 @@ $bgcolor = $light; } - echo ''.$tags[$report['tag']].' '.$report['subject'].''.$value.''; + echo ''.$tags[$report['tag']].' '.escapeHtml($report['subject']).''.$value.''; $showed=true; }