Merge branch 'ent-10162-stored-cross-site-scripting-special-days-module' into 'develop'

Ent 10162 stored cross site scripting special days module

See merge request artica/pandorafms!5444
This commit is contained in:
Daniel Rodriguez 2023-02-02 14:29:14 +00:00
commit f28a4d0f28
2 changed files with 2 additions and 2 deletions

View File

@ -900,7 +900,7 @@ class CalendarManager
$id_group = get_parameter('id_group', null);
$day_code = get_parameter('day_code', null);
$id_calendar = get_parameter('id_calendar', null);
$description = get_parameter('description', null);
$description = io_safe_input(get_parameter('description', null));
$change = true;
if ($new === false
&& ($date === $specialDay->date()

View File

@ -140,7 +140,7 @@ $inputs[] = [
'type' => 'textarea',
'name' => 'description',
'required' => false,
'value' => $specialDay->description(),
'value' => io_safe_output($specialDay->description()),
'rows' => 50,
'columns' => 30,
],