From e98c525dd3c4da292bc296fe61a644b55949416e Mon Sep 17 00:00:00 2001 From: Tiago Brito Date: Wed, 20 Nov 2013 11:34:14 +0000 Subject: [PATCH] convert $title and $th special characters to HTML --- src/Monolog/Formatter/HtmlEmailFormatter.php | 3 +++ 1 file changed, 3 insertions(+) diff --git a/src/Monolog/Formatter/HtmlEmailFormatter.php b/src/Monolog/Formatter/HtmlEmailFormatter.php index 662eeef8..056bf13b 100644 --- a/src/Monolog/Formatter/HtmlEmailFormatter.php +++ b/src/Monolog/Formatter/HtmlEmailFormatter.php @@ -50,6 +50,7 @@ class HtmlEmailFormatter extends NormalizerFormatter */ private function addRow($th, $td = ' ') { + $th = htmlspecialchars($th); $td = '
'.htmlspecialchars($td).'
'; return "\n$th:\n".$td."\n"; @@ -64,6 +65,8 @@ class HtmlEmailFormatter extends NormalizerFormatter */ private function addTitle($title, $level) { + $title = htmlspecialchars($title); + return '

'.$title.'

'; } /**