From 6846268aac8ef9563b2b7a52f41fe642ff94854d Mon Sep 17 00:00:00 2001 From: Harald Eilertsen Date: Sat, 12 Mar 2022 17:04:58 +0100 Subject: Security: Escape band and venue name in concerts table. --- includes/admin/views/_concerts_table.php | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'includes') diff --git a/includes/admin/views/_concerts_table.php b/includes/admin/views/_concerts_table.php index 484adca..885f0c0 100644 --- a/includes/admin/views/_concerts_table.php +++ b/includes/admin/views/_concerts_table.php @@ -298,8 +298,8 @@ if (!class_exists("GiglogAdmin_ConcertsTable")) $content .= "" . date( 'd.M.Y', strtotime( $concert->cdate() ) ) . "" - . "{$concert->cname()}" - . "{$concert->venue()->name()}"; + . "" . esc_html($concert->cname()) . "" + . "" . esc_html($concert->venue()->name()) . ""; if( is_admin() ) { $content .= '' . $this->mark_new_concert($concert) . ''; -- cgit v1.2.3