fix: Escape EXIF tags in ML properties view (#598)

This commit is contained in:
onli 2019-03-18 22:40:58 +01:00
parent b6cbaee339
commit 99b8190180
2 changed files with 6 additions and 2 deletions

View File

@ -1,7 +1,11 @@
Version 2.2.1-alpha2 ()
------------------------------------------------------------------------
* Security: Fix XSS in Media Library by interpreted EXIF tags
(thanks @hannob!)
* Allow to receive multiple trackbacks and pingbacks
(thanks @mitch!)
* Fallback for $lang variable when configuration failed to load,
which evades some unuseful error messages (thanks @HQJaTu!)

View File

@ -241,8 +241,8 @@
<dl class="clearfix">
{foreach $meta_data AS $meta_value}
<dt>{$meta_value@key}</dt>
<dd>{if is_array($meta_value)}{$meta_value|print_r}{else}{$meta_value|formatTime:DATE_FORMAT_SHORT:false:$meta_value@key}{/if}</dd>
<dt>{$meta_value@key|escape}</dt>
<dd>{if is_array($meta_value)}{$meta_value|print_r}{else}{$meta_value|formatTime:DATE_FORMAT_SHORT:false:$meta_value@key|escape}{/if}</dd>
{/foreach}
</dl>