Skip to content

Commit 3564cff

Browse files
committed
Added protection against use of JS in users page description
1 parent 4dd317b commit 3564cff

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

app/Http/Controllers/UserController.php

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -526,7 +526,8 @@ public function editPage(request $request)
526526

527527
$profilePhoto = $request->file('image');
528528
$pageName = $request->pageName;
529-
$pageDescription = $request->pageDescription;
529+
$pageDescription = strip_tags($request->pageDescription,'<a><p><strong><i><ul><ol><li><blockquote><h2><h3><h4>');
530+
$pageDescription = preg_replace("/<a([^>]*)>/i", "<a $1 rel=\"noopener noreferrer nofollow\">", $pageDescription);
530531
$name = $request->Name;
531532

532533
User::where('id', $userId)->update(['littlelink_name' => $pageName, 'littlelink_description' => $pageDescription, 'name' => $name]);

0 commit comments

Comments
 (0)