This commit is contained in:
Ian 2014-09-19 16:37:15 +02:00
parent 8ff9b85b9d
commit 218b2941e7
2 changed files with 3 additions and 1 deletions

View file

@ -9,6 +9,7 @@ fix XSS security vulnerability (Thanks to Stefan Schurtz!)
latest: Smarty3 forward compatibility
1.14:
-----
Added check to circument adduser plugin's "registered only" option.

View file

@ -343,7 +343,8 @@ class serendipity_event_contactform extends serendipity_event {
htmlspecialchars(strip_tags($serendipity['POST']['name'])),
htmlspecialchars(strip_tags($serendipity['POST']['email'])),
htmlspecialchars(strip_tags($serendipity['POST']['url'])),
htmlspecialchars(strip_tags($comment,true)))) {
htmlspecialchars(strip_tags($comment)),
true)) {
$serendipity['smarty']->assign('is_contactform_sent', true);
return true;