]> git.immae.eu Git - github/wallabag/wallabag.git/commitdiff
views: escape piwik host and siteId to prevent XSS cve-2018-11352
authorKevin Decherf <kevin@kdecherf.com>
Sun, 23 Sep 2018 20:46:09 +0000 (22:46 +0200)
committerKevin Decherf <kevin@kdecherf.com>
Sun, 23 Sep 2018 20:46:09 +0000 (22:46 +0200)
Fixes CVE-2018-11352

Signed-off-by: Kevin Decherf <kevin@kdecherf.com>
src/Wallabag/CoreBundle/Resources/views/base.html.twig

index 2499bb887adb87f2b2b99271f47dec83b168f59d..498619466fffdcd20a11366b748b53563dae5b17 100644 (file)
@@ -69,7 +69,7 @@
         {% block footer %}{% endblock %}
 
         {% if craue_setting('piwik_enabled') %}
-            {{ piwik(craue_setting('piwik_host'), craue_setting('piwik_site_id')) }}
+            {{ piwik(craue_setting('piwik_host')|e('html_attr'), craue_setting('piwik_site_id')|e('html_attr')) }}
         {% endif %}
     </body>
 </html>