[CVE-2020-9311] Escape First Name when displaying re-login screen

This commit is contained in:
Maxime Rainville 2020-04-23 16:41:04 +12:00
parent 8f9bb9d03a
commit d3b23e7024
2 changed files with 2 additions and 2 deletions

View File

@ -86,7 +86,7 @@ class CMSSecurity extends Security {
'CMSSecurity.TimedOutTitleMember',
'Hey {name}!<br />Your session has timed out.',
'Title for CMS popup login form for a known user',
array('name' => $member->FirstName)
array('name' => Convert::raw2xml($member->FirstName))
);
} else {
return _t(

View File

@ -139,7 +139,7 @@ JS;
$this->message = _t(
'Member.LOGGEDINAS',
"You're logged in as {name}.",
array('name' => $member->{$this->loggedInAsField})
array('name' => Convert::raw2xml($member->{$this->loggedInAsField}))
);
}