Add precautionary purify
authorEileen McNaughton <emcnaughton@wikimedia.org>
Thu, 7 Jul 2022 08:58:14 +0000 (20:58 +1200)
committerEileen McNaughton <emcnaughton@wikimedia.org>
Thu, 7 Jul 2022 09:00:16 +0000 (21:00 +1200)
templates/CRM/common/info.tpl
templates/CRM/common/status.tpl

index 1435bc370291694e1789eeb01120295b4ac1c081..a54e9e65a94d0fbacfa4a8f5d188f7d28c24846a 100644 (file)
@@ -12,6 +12,6 @@
   <div class="messages status {$infoType}"{if $infoOptions} data-options='{$infoOptions|smarty:nodefaults}'{/if}>
     {icon icon="fa-info-circle"}{/icon}
     <span class="msg-title">{$infoTitle}</span>
-    <span class="msg-text">{$infoMessage|smarty:nodefaults}</span>
+    <span class="msg-text">{$infoMessage|smarty:nodefaults|purify}</span>
   </div>
 {/if}
index 098055e539ba73c4860f8644e6c87f8298a0a443..fa36d7ec59279d0550f1051d5760875898f8c73c 100644 (file)
@@ -17,6 +17,6 @@
     {else}
       {assign var="infoType" value=$statItem.type}
     {/if}
-    {include file="CRM/common/info.tpl" infoTitle=$statItem.title|smarty:nodefaults infoMessage=$statItem.text|smarty:nodefaults infoOptions=$statItem.options|smarty:nodefaults|@json_encode}
+    {include file="CRM/common/info.tpl" infoTitle=$statItem.title infoMessage=$statItem.text|smarty:nodefaults|purify infoOptions=$statItem.options|smarty:nodefaults|@json_encode}
   {/foreach}
 {/if}