Uploaded image for project: 'phpBB3'
  1. phpBB3
  2. PHPBB3-15600

Ban reasons are not escaped in mcp_ban.html template

    XMLWordPrintable

Details

    • Bug
    • Status: Closed (View Workflow)
    • Major
    • Resolution: Fixed
    • 3.3, 3.2.2
    • 4.0.0-a1, 3.2.4-RC1
    • None
    • PHP 7.2.3, PostgreSQL 9.6, Chrome 65.0.3325.181

    Description

      Technically it is possible to store multiline ban reasons in database, however this breaks unescaped JavaScript code stored in template.

      I suggest to use TWIG e('js') function to fix this issue.

      Attachments

        Activity

          People

            Marc Marc
            Tarzanych Tarzanych [X] (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: