From 558f03f0f84a142438de9844b2047be2f050c385 Mon Sep 17 00:00:00 2001 From: cash Date: Sat, 5 Nov 2011 16:42:59 -0400 Subject: Fixes #4023 escaping alt and title attributes in icon views --- mod/file/views/default/icon/object/file.php | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) (limited to 'mod/file') diff --git a/mod/file/views/default/icon/object/file.php b/mod/file/views/default/icon/object/file.php index ff729da94..51a4469e9 100644 --- a/mod/file/views/default/icon/object/file.php +++ b/mod/file/views/default/icon/object/file.php @@ -5,7 +5,7 @@ * @uses $vars['entity'] The entity the icon represents - uses getIconURL() method * @uses $vars['size'] topbar, tiny, small, medium (default), large, master * @uses $vars['href'] Optional override for link - * @uses $vars['link_class'] Optional CSS class added to img + * @uses $vars['link_class'] Optional CSS class added to link */ $entity = $vars['entity']; @@ -17,6 +17,7 @@ if (!in_array($vars['size'], $sizes)) { } $title = $entity->title; +$title = htmlspecialchars($title, ENT_QUOTES, 'UTF-8', false); $url = $entity->getURL(); if (isset($vars['href'])) { -- cgit v1.2.3