From db52c6df4c1120132aab44da65af9963f71b5f88 Mon Sep 17 00:00:00 2001 From: Kijin Sung Date: Sat, 11 Apr 2026 20:46:50 +0900 Subject: [PATCH] Fix double-escape of homepage field #2695 --- modules/document/document.controller.php | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/modules/document/document.controller.php b/modules/document/document.controller.php index 5c3fca3c4..07f2bc7eb 100644 --- a/modules/document/document.controller.php +++ b/modules/document/document.controller.php @@ -641,7 +641,7 @@ class DocumentController extends Document if (!empty($obj->homepage)) { - $obj->homepage = escape($obj->homepage); + $obj->homepage = escape($obj->homepage, false); if(!preg_match('/^[a-z]+:\/\//i',$obj->homepage)) { $obj->homepage = 'http://'.$obj->homepage; @@ -1077,7 +1077,7 @@ class DocumentController extends Document if($obj->commentStatus == 'DENY') $this->_checkCommentStatusForOldVersion($obj); if($obj->homepage) { - $obj->homepage = escape($obj->homepage); + $obj->homepage = escape($obj->homepage, false); if(!preg_match('/^[a-z]+:\/\//i',$obj->homepage)) { $obj->homepage = 'http://'.$obj->homepage;