Fix HTML injection exploit (#682)

Escape html special characters from the $fields array to prevent html injection in the generated pdfs.
This commit is contained in:
Sanchit Sharma
2022-01-12 23:09:15 +11:00
committed by GitHub
parent d303b1a71c
commit e2bb414efe

View File

@ -157,6 +157,10 @@ trait GeneratesPdfTrait
foreach ($customerCustomFields as $customField) {
$fields['{'.$customField->customField->slug.'}'] = $customField->defaultAnswer;
}
foreach ($fields as $key => $field) {
$fields[$key] = htmlspecialchars($field, ENT_QUOTES, 'UTF-8');
}
return $fields;
}