diff options
author | cash <cash.costello@gmail.com> | 2011-11-05 16:42:59 -0400 |
---|---|---|
committer | cash <cash.costello@gmail.com> | 2011-11-05 16:42:59 -0400 |
commit | 558f03f0f84a142438de9844b2047be2f050c385 (patch) | |
tree | d79fb8e6874d2b0a9935b1737e76b32d7d5d9942 /mod/file/views/default/icon | |
parent | b5f88f3e8836464bd9939ac296b673c4b199bf0a (diff) | |
download | elgg-558f03f0f84a142438de9844b2047be2f050c385.tar.gz elgg-558f03f0f84a142438de9844b2047be2f050c385.tar.bz2 |
Fixes #4023 escaping alt and title attributes in icon views
Diffstat (limited to 'mod/file/views/default/icon')
-rw-r--r-- | mod/file/views/default/icon/object/file.php | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/mod/file/views/default/icon/object/file.php b/mod/file/views/default/icon/object/file.php index ff729da94..51a4469e9 100644 --- a/mod/file/views/default/icon/object/file.php +++ b/mod/file/views/default/icon/object/file.php @@ -5,7 +5,7 @@ * @uses $vars['entity'] The entity the icon represents - uses getIconURL() method * @uses $vars['size'] topbar, tiny, small, medium (default), large, master * @uses $vars['href'] Optional override for link - * @uses $vars['link_class'] Optional CSS class added to img + * @uses $vars['link_class'] Optional CSS class added to link */ $entity = $vars['entity']; @@ -17,6 +17,7 @@ if (!in_array($vars['size'], $sizes)) { } $title = $entity->title; +$title = htmlspecialchars($title, ENT_QUOTES, 'UTF-8', false); $url = $entity->getURL(); if (isset($vars['href'])) { |