From 57fce758f5bd116e1f603d6435fb341f2741ab16 Mon Sep 17 00:00:00 2001 From: Alexandre Alapetite Date: Wed, 28 Nov 2018 22:16:14 +0100 Subject: [PATCH] Fix HTML injections (#2157) Minz: Fix HTML injections --- app/views/error/index.phtml | 2 +- lib/Minz/ActionException.php | 4 +--- lib/Minz/ControllerNotExistException.php | 4 +--- 3 files changed, 3 insertions(+), 7 deletions(-) diff --git a/app/views/error/index.phtml b/app/views/error/index.phtml index fe3abf8c4..8fd74e8bf 100644 --- a/app/views/error/index.phtml +++ b/app/views/error/index.phtml @@ -2,7 +2,7 @@

code; ?>

- errorMessage; ?>
+ errorMessage, ENT_NOQUOTES, 'UTF-8'); ?>

diff --git a/lib/Minz/ActionException.php b/lib/Minz/ActionException.php index f1f70c1bc..311f15086 100644 --- a/lib/Minz/ActionException.php +++ b/lib/Minz/ActionException.php @@ -1,9 +1,7 @@