From b3d388c234327ec226e1ddfca29a8bf00ecea50f Mon Sep 17 00:00:00 2001 From: Tim Hunt Date: Tue, 24 Feb 2015 17:35:32 +0000 Subject: [PATCH] MDL-49284 formslib: fix strict validation of HTML. --- lib/formslib.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/formslib.php b/lib/formslib.php index b6f0c179a16..88564a784ad 100644 --- a/lib/formslib.php +++ b/lib/formslib.php @@ -2905,7 +2905,7 @@ class MoodleQuickForm_Rule_Required extends HTML_QuickForm_Rule { global $CFG; if (!empty($CFG->strictformsrequired)) { if (!empty($format) && $format == FORMAT_HTML) { - return array('', "{jsVar}.replace(/(<[^img|hr|canvas]+>)| |\s+/ig, '') == ''"); + return array('', "{jsVar}.replace(/(<(?!img|hr|canvas)[^>]*>)| |\s+/ig, '') == ''"); } else { return array('', "{jsVar}.replace(/^\s+$/g, '') == ''"); }