Skip to:
Content

BuddyPress.org

Changeset 12375


Ignore:
Timestamp:
04/25/2019 02:31:35 PM (7 years ago)
Author:
boonebgorges
Message:

Groups: Improved escaping when editing group details.

Location:
trunk/src/bp-templates
Files:
3 edited

Legend:

Unmodified
Added
Removed
  • trunk/src/bp-templates/bp-legacy/buddypress/groups/create.php

    r12082 r12375  
    7474                <div>
    7575                    <label for="group-name"><?php _e( 'Group Name (required)', 'buddypress' ); ?></label>
    76                     <input type="text" name="group-name" id="group-name" aria-required="true" value="<?php bp_new_group_name(); ?>" />
     76                    <input type="text" name="group-name" id="group-name" aria-required="true" value="<?php echo esc_attr( bp_get_new_group_name() ); ?>" />
    7777                </div>
    7878
  • trunk/src/bp-templates/bp-legacy/buddypress/groups/single/admin/edit-details.php

    r12082 r12375  
    2222
    2323<label for="group-name"><?php _e( 'Group Name (required)', 'buddypress' ); ?></label>
    24 <input type="text" name="group-name" id="group-name" value="<?php bp_group_name(); ?>" aria-required="true" />
     24<input type="text" name="group-name" id="group-name" value="<?php echo esc_attr( bp_get_group_name() ); ?>" aria-required="true" />
    2525
    2626<label for="group-desc"><?php _e( 'Group Description (required)', 'buddypress' ); ?></label>
  • trunk/src/bp-templates/bp-nouveau/buddypress/groups/single/admin/edit-details.php

    r12290 r12375  
    2424
    2525<label for="group-name"><?php esc_html_e( 'Group Name (required)', 'buddypress' ); ?></label>
    26 <input type="text" name="group-name" id="group-name" value="<?php bp_is_group_create() ? bp_new_group_name() : bp_group_name(); ?>" aria-required="true" />
     26<input type="text" name="group-name" id="group-name" value="<?php if ( bp_is_group_create() ) : echo esc_attr( bp_get_new_group_name() ); else : echo esc_attr( bp_get_group_name() ); endif; ?>" aria-required="true" />
    2727
    2828<label for="group-desc"><?php esc_html_e( 'Group Description (required)', 'buddypress' ); ?></label>
Note: See TracChangeset for help on using the changeset viewer.