FIX StringTagField now works with SS-2018-021/CVE-2019-5715 by serialising arrays before write

This commit is contained in:
Robbie Averill 2019-02-19 11:09:31 +07:00
parent e941dbfc26
commit 2c40955c2d
1 changed files with 13 additions and 3 deletions

View File

@ -205,9 +205,19 @@ class StringTagField extends DropdownField {
$name = $this->getName();
$record->$name = join(',', $this->Value());
$record->write();
}
$record->$name = $this->dataValue();
$record->write();
}
/**
* Ensure that arrays are imploded before being saved
*
* @return mixed|string
*/
public function dataValue()
{
return implode(',', $this->value);
}
/**
* Returns a JSON string of tags, for lazy loading.