1
0
mirror of https://github.com/phpbb/phpbb.git synced 2025-07-23 10:01:55 +02:00

[ticket/security/279] Use rawurlencode for escaping smilie URLs

SECURITY-279
This commit is contained in:
Derky
2023-09-21 15:41:20 +02:00
committed by Marc Alexander
parent d8ac6f575e
commit c4f42c1573

View File

@@ -654,7 +654,7 @@ class acp_icons
{
$replace_sql = ($mode == 'smilies') ? $code : $img;
$sql = array(
$fields . '_url' => utf8_substr(htmlspecialchars($img, ENT_COMPAT), 0, 50),
$fields . '_url' => utf8_substr(rawurlencode($img), 0, 50),
$fields . '_height' => (int) $height,
$fields . '_width' => (int) $width,
'display_on_posting' => (int) $display_on_posting,
@@ -676,7 +676,7 @@ class acp_icons
++$order;
$sql = array(
$fields . '_url' => utf8_substr(htmlspecialchars($img, ENT_COMPAT), 0, 50),
$fields . '_url' => utf8_substr(rawurlencode($img), 0, 50),
$fields . '_height' => (int) $height,
$fields . '_width' => (int) $width,
$fields . '_order' => (int) $order,