Skip to content

Commit 172e9fa

Browse files
committed
Security: Exercise: remove XSS when showing feedback
See advisory GHSA-59h4-34mx-m67m
1 parent e63b2c5 commit 172e9fa

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

main/inc/lib/exercise.lib.php

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6258,6 +6258,8 @@ public static function getNotCorrectedYetText()
62586258
*/
62596259
public static function getFeedbackText($message)
62606260
{
6261+
$message = Security::remove_XSS($message);
6262+
62616263
return Display::return_message($message, 'warning', false);
62626264
}
62636265

0 commit comments

Comments
 (0)