Make WordPress Core


Ignore:
Timestamp:
03/26/2014 02:38:39 PM (10 years ago)
Author:
nacin
Message:

Upgrader skins: Strip tags before displaying error data.

fixes #25394.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/src/wp-admin/includes/class-wp-upgrader-skins.php

    r27280 r27737  
    6666            foreach ( $errors->get_error_messages() as $message ) {
    6767                if ( $errors->get_error_data() && is_string( $errors->get_error_data() ) )
    68                     $this->feedback($message . ' ' . esc_html( $errors->get_error_data() ) );
     68                    $this->feedback($message . ' ' . esc_html( strip_tags( $errors->get_error_data() ) ) );
    6969                else
    7070                    $this->feedback($message);
     
    218218            foreach ( $error->get_error_messages() as $emessage ) {
    219219                if ( $error->get_error_data() && is_string( $error->get_error_data() ) )
    220                     $messages[] = $emessage . ' ' . esc_html( $error->get_error_data() );
     220                    $messages[] = $emessage . ' ' . esc_html( strip_tags( $error->get_error_data() ) );
    221221                else
    222222                    $messages[] = $emessage;
Note: See TracChangeset for help on using the changeset viewer.