RVE-2024-1 missing escape of autogenerated document title

This commit is contained in:
Kijin Sung 2024-01-20 00:39:19 +09:00
parent 40b3dcd5f0
commit a3650bb899

View file

@ -750,7 +750,7 @@ class DocumentController extends Document
$obj->title = escape($obj->title, false);
if($obj->title == '')
{
$obj->title = cut_str(trim(strip_tags(nl2br($obj->content))),20,'...');
$obj->title = escape(cut_str(trim(utf8_normalize_spaces(strip_tags($obj->content))), 20, '...'), false);
}
if($obj->title == '')
{