Ticket #14996: media.patch
| File media.patch, 1.3 KB (added by layotte, 3 years ago) |
|---|
-
media.php
612 612 if ( !empty($href) && !strpos($href, '://') ) 613 613 $href = "http://$href"; 614 614 615 $title = esc_attr( $_POST['insertonly']['title']);615 $title = esc_attr(stripslashes($_POST['insertonly']['title'])); 616 616 if ( empty($title) ) 617 617 $title = esc_attr( basename($href) ); 618 618 … … 670 670 if ( !empty($href) && !strpos($href, '://') ) 671 671 $href = "http://$href"; 672 672 673 $title = esc_attr( $_POST['insertonly']['title']);673 $title = esc_attr(stripslashes($_POST['insertonly']['title'])); 674 674 if ( empty($title) ) 675 675 $title = esc_attr( basename($href) ); 676 676 … … 728 728 if ( !empty($href) && !strpos($href, '://') ) 729 729 $href = "http://$href"; 730 730 731 $title = esc_attr( $_POST['insertonly']['title']);731 $title = esc_attr(stripslashes($_POST['insertonly']['title'])); 732 732 if ( empty($title) ) 733 733 $title = basename($href); 734 734 735 if ( !empty($title) && !empty($href) ) 735 736 $html = "<a href='" . esc_url($href) . "' >$title</a>"; 737 736 738 $html = apply_filters('file_send_to_editor_url', $html, esc_url_raw($href), $title); 739 737 740 return media_send_to_editor($html); 738 741 }