aboutsummaryrefslogtreecommitdiff
path: root/mod/file
diff options
context:
space:
mode:
authorSteve Clay <steve@mrclay.org>2012-09-09 01:52:09 -0400
committerSteve Clay <steve@mrclay.org>2012-10-10 21:01:56 -0400
commit5efa9426d40326b8d31c152dd2a433076b490308 (patch)
treed94abfb8194e126fbebcbf50b751f9e796e9a9a7 /mod/file
parent9ccbd106a87a1742a61cc4df0e9ead921046772a (diff)
downloadelgg-5efa9426d40326b8d31c152dd2a433076b490308.tar.gz
elgg-5efa9426d40326b8d31c152dd2a433076b490308.tar.bz2
Fixes #4593: All titles are HTML-escaped plain text
Diffstat (limited to 'mod/file')
-rw-r--r--mod/file/actions/file/upload.php4
1 files changed, 2 insertions, 2 deletions
diff --git a/mod/file/actions/file/upload.php b/mod/file/actions/file/upload.php
index d72d04eb7..d6dce2528 100644
--- a/mod/file/actions/file/upload.php
+++ b/mod/file/actions/file/upload.php
@@ -6,7 +6,7 @@
*/
// Get variables
-$title = get_input("title");
+$title = htmlspecialchars(get_input('title', '', false), ENT_QUOTES, 'UTF-8');
$desc = get_input("description");
$access_id = (int) get_input("access_id");
$container_guid = (int) get_input('container_guid', 0);
@@ -44,7 +44,7 @@ if ($new_file) {
// if no title on new upload, grab filename
if (empty($title)) {
- $title = $_FILES['upload']['name'];
+ $title = htmlspecialchars($_FILES['upload']['name'], ENT_QUOTES, 'UTF-8');
}
} else {