Uploaded image for project: 'phpBB'
  1. phpBB
  2. PHPBB-15600

Ban reasons are not escaped in mcp_ban.html template

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Major Major
    • 4.0.0-a1, 3.2.4-RC1
    • 3.3, 3.2.2
    • None
    • PHP 7.2.3, PostgreSQL 9.6, Chrome 65.0.3325.181

      Technically it is possible to store multiline ban reasons in database, however this breaks unescaped JavaScript code stored in template.

      I suggest to use TWIG e('js') function to fix this issue.

            Marc Marc
            Tarzanych Tarzanych [X] (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: