File tree 2 files changed +7
-3
lines changed
2 files changed +7
-3
lines changed Original file line number Diff line number Diff line change @@ -181,6 +181,10 @@ public function __construct(
181
181
'name ' => 'date_to_time_ago ' ,
182
182
'callable ' => 'Display::dateToStringAgoAndLongDate ' ,
183
183
],
184
+ [
185
+ 'name ' => 'remove_xss ' ,
186
+ 'callable ' => 'Security::remove_XSS ' ,
187
+ ],
184
188
];
185
189
186
190
foreach ($ filters as $ filter ) {
Original file line number Diff line number Diff line change 102
102
{% set linkedin_url = ' ' %}
103
103
{% for extra in user.extra %}
104
104
{% if extra.value.getField().getVariable() == ' skype' %}
105
- {% set skype_account = extra.value.getValue() | escape %}
105
+ {% set skype_account = extra.value.getValue() | remove_xss %}
106
106
{% endif %}
107
107
108
108
{% if extra.value.getField().getVariable() == ' linkedin_url' %}
109
- {% set linkedin_url = extra.value.getValue() | escape %}
109
+ {% set linkedin_url = extra.value.getValue() | remove_xss %}
110
110
{% endif %}
111
111
{% endfor %}
112
112
145
145
{% for item in extra_info %}
146
146
{% if item.variable != ' langue_cible' %}
147
147
<dt >{ { item.label } }:</dt >
148
- <dd >{ { item.value } }</dd >
148
+ <dd >{ { item.value | remove_xss } }</dd >
149
149
{% endif %}
150
150
{% endfor %}
151
151
</dl >
You can’t perform that action at this time.
0 commit comments