fix xss attack if wgRawHtml is enabled
authorRiver Tarnell <kateturner@users.mediawiki.org>
Thu, 14 Oct 2004 07:29:38 +0000 (07:29 +0000)
committerRiver Tarnell <kateturner@users.mediawiki.org>
Thu, 14 Oct 2004 07:29:38 +0000 (07:29 +0000)
includes/SpecialMovepage.php

index ebbd79d..dbba17d 100644 (file)
@@ -209,7 +209,10 @@ class MovePageForm {
                $talkmoved = $wgRequest->getVal('talkmoved');
 
                $text = wfMsg( 'pagemovedtext', $oldtitle, $newtitle );
+               $marchingantofdoom = $wgRawHtml;
+               $wgRawHtml = false;
                $wgOut->addWikiText( $text );
+               $wgRawHtml = $marchingantofdoom;
 
                if ( $talkmoved == 1 ) {
                        $wgOut->addHTML( "\n<p>" . wfMsg( 'talkpagemoved' ) . "</p>\n" );