Skip to content

Commit 399b16a

Browse files
committed
XSS Lücke behoben
1 parent 1468d8e commit 399b16a

File tree

2 files changed

+7
-2
lines changed

2 files changed

+7
-2
lines changed

files/lib/system/gridView/admin/DiscordWebhookGridView.class.php

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,7 @@
1717
use wcf\system\view\filter\TextFilter;
1818
use wcf\system\view\filter\TimeFilter;
1919
use wcf\system\WCF;
20+
use wcf\util\StringUtil;
2021

2122
final class DiscordWebhookGridView extends AbstractGridView
2223
{
@@ -41,7 +42,11 @@ public function render(mixed $value, DatabaseObject $row): string
4142
return $value;
4243
}
4344

44-
return \sprintf('%s<br>(%s)', $channels[$row->botID][$value]['name'], $value);
45+
return \sprintf(
46+
'%s<br>(%s)',
47+
StringUtil::encodeHTML($channels[$row->botID][$value]['name']),
48+
StringUtil::encodeHTML($value)
49+
);
4550
}
4651
},
4752
])

package.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@
77
<packagedescription>API to cummincate with Discord.</packagedescription>
88
<packagedescription language="de">API um mit Discord zu kommunizieren.</packagedescription>
99
<version>2.8.0</version>
10-
<date>2025-11-12</date>
10+
<date>2025-11-14</date>
1111
<license>https://creativecommons.org/publicdomain/zero/1.0/deed.en</license>
1212
</packageinformation>
1313
<authorinformation>

0 commit comments

Comments
 (0)