You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
If the the text phrase with var_name="align_left" contains a quote ', the complete site gets unusable because the generated javascript code is broken as it is not escaped with a backslash \'. It produces a hundred of errors that can be seen on the javascript console.
Steps to reproduce:
Add a quote in the phrase var_name="align_left" (see screenshot below)
What's expected?
All localized strings should be properly escaped. Quotes should be escaped with a backslash.
Server information
PHP Version 7.3.28
phpFox version
phpfox 4.8.8 (problem did not exist on previous versions)
Screenshots
Database entry:
Broken JS code:
Text correctly escaped with backslash marked in blue. Affected text not escaped marked in red (backslash is missing).
Notices
Other phrases seem to be correctly escaped (see screenshot above)
Other phrases might be also affected?
The text was updated successfully, but these errors were encountered:
What's happened?
If the the text phrase with var_name="align_left" contains a quote
'
, the complete site gets unusable because the generated javascript code is broken as it is not escaped with a backslash\'
. It produces a hundred of errors that can be seen on the javascript console.Steps to reproduce:
What's expected?
All localized strings should be properly escaped. Quotes should be escaped with a backslash.
Server information
PHP Version 7.3.28
phpFox version
phpfox 4.8.8 (problem did not exist on previous versions)
Screenshots
Database entry:
data:image/s3,"s3://crabby-images/0dd38/0dd38bfa3991bc7f6eced6bdfae1b22bfbe05c1e" alt="alinea"
Broken JS code:
data:image/s3,"s3://crabby-images/62cf4/62cf4425d042c957cc808d997b209a2647dc483a" alt="htmljscode"
Text correctly escaped with backslash marked in blue. Affected text not escaped marked in red (backslash is missing).
Notices
The text was updated successfully, but these errors were encountered: