From 6af2c4ad0e288fae5702e96391657d173bba2297 Mon Sep 17 00:00:00 2001 From: Matthew Noorenberghe Date: Sat, 9 Feb 2019 18:06:21 -0800 Subject: [PATCH] Escape output of WEB_TITLE, HOME_URL, HOME_CONTENT, & WEB_CONSOLE_BANNER. Fixes #2468 --- web/skins/classic/includes/functions.php | 8 ++++---- web/skins/classic/views/login.php | 2 +- web/skins/classic/views/logout.php | 2 +- web/skins/classic/views/none.php | 2 +- web/skins/classic/views/postlogin.php | 2 +- 5 files changed, 8 insertions(+), 8 deletions(-) diff --git a/web/skins/classic/includes/functions.php b/web/skins/classic/includes/functions.php index 703cd49d3..063977942 100644 --- a/web/skins/classic/includes/functions.php +++ b/web/skins/classic/includes/functions.php @@ -57,7 +57,7 @@ function xhtmlHeaders( $file, $title ) { - <?php echo ZM_WEB_TITLE_PREFIX ?> - <?php echo validHtmlStr($title) ?> + <?php echo validHtmlStr(ZM_WEB_TITLE_PREFIX); ?> - <?php echo validHtmlStr($title) ?> @@ -254,7 +254,7 @@ function getNavBarHTML($reload = null) { - + -

account_circle

+

account_circle

diff --git a/web/skins/classic/views/logout.php b/web/skins/classic/views/logout.php index 772bacd80..1b38d812f 100644 --- a/web/skins/classic/views/logout.php +++ b/web/skins/classic/views/logout.php @@ -25,7 +25,7 @@ xhtmlHeaders(__FILE__, translate('Logout') );
diff --git a/web/skins/classic/views/none.php b/web/skins/classic/views/none.php index da04ed19b..1213b44d5 100644 --- a/web/skins/classic/views/none.php +++ b/web/skins/classic/views/none.php @@ -25,7 +25,7 @@ $skinJsFile = getSkinFile('js/skin.js'); - <?php echo ZM_WEB_TITLE_PREFIX ?> + <?php echo validHtmlStr(ZM_WEB_TITLE_PREFIX); ?>