Skip to content

Commit 3b98682

Browse files
committed
Security: Social: Remove XSS when displaying group messages
1 parent 7a0e10c commit 3b98682

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

main/inc/lib/message.lib.php

+3-1
Original file line numberDiff line numberDiff line change
@@ -1941,7 +1941,9 @@ public static function display_message_for_group($groupId, $topic_id)
19411941
$main_content .= '<div class="message-content"> ';
19421942
$main_content .= '<div class="username">'.$user_link.'</div>';
19431943
$main_content .= $date;
1944-
$main_content .= '<div class="message">'.$main_message['content'].$attachment.'</div></div>';
1944+
$main_content .= '<div class="message">'
1945+
.Security::remove_XSS($main_message['content'], STUDENT, true)
1946+
.$attachment.'</div></div>';
19451947
$main_content .= '</div>';
19461948
$main_content .= '</div>';
19471949

0 commit comments

Comments
 (0)