mirror of
https://github.com/silverstripe/silverstripe-framework
synced 2024-10-22 14:05:37 +02:00
[CVE-2020-9311] Escape First Name when displaying re-login screen
This commit is contained in:
parent
8f9bb9d03a
commit
d3b23e7024
@ -86,7 +86,7 @@ class CMSSecurity extends Security {
|
||||
'CMSSecurity.TimedOutTitleMember',
|
||||
'Hey {name}!<br />Your session has timed out.',
|
||||
'Title for CMS popup login form for a known user',
|
||||
array('name' => $member->FirstName)
|
||||
array('name' => Convert::raw2xml($member->FirstName))
|
||||
);
|
||||
} else {
|
||||
return _t(
|
||||
|
@ -139,7 +139,7 @@ JS;
|
||||
$this->message = _t(
|
||||
'Member.LOGGEDINAS',
|
||||
"You're logged in as {name}.",
|
||||
array('name' => $member->{$this->loggedInAsField})
|
||||
array('name' => Convert::raw2xml($member->{$this->loggedInAsField}))
|
||||
);
|
||||
}
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user