Skip to content
Snippets Groups Projects

Issue #3488731: Prevent links from being injected into facets

Open Karl Yoder requested to merge issue/facetapi-3488731:3488731-links-can-be into 7.x-1.x
1 file
+ 1
1
Compare changes
  • Side-by-side
  • Inline
@@ -317,7 +317,7 @@ abstract class FacetapiAdapter {
$parts = explode(':', $filter, 2);
// We need to filter out possible XSS attack function calls.
foreach ($parts as $id => $part) {
$parts[$id] = htmlspecialchars_decode(filter_xss($part));
$parts[$id] = htmlspecialchars_decode(filter_xss($part, []));
}
$field_alias = rawurldecode($parts[0]);
if (isset($parts[1]) && isset($enabled_aliases[$field_alias])) {
Loading