From 09ff4eba5358136fd10e6669b66a5c0ede6bfda3 Mon Sep 17 00:00:00 2001 From: iglocska Date: Sun, 18 Sep 2022 18:27:39 +0200 Subject: [PATCH] fix: [xss] resolved in the genericField of the single view - as reported by SK-CERT --- .../genericElements/SingleViews/Fields/genericField.php | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/templates/element/genericElements/SingleViews/Fields/genericField.php b/templates/element/genericElements/SingleViews/Fields/genericField.php index f2f4f5d..ad99eea 100644 --- a/templates/element/genericElements/SingleViews/Fields/genericField.php +++ b/templates/element/genericElements/SingleViews/Fields/genericField.php @@ -22,7 +22,9 @@ if (!empty($field['url'])) { '%s', $baseurl, h($field['url']), - $string + h($string) ); +} else { + $string = h($string); } echo $string;