page-credits: htmlentities *everywhere*

This commit is contained in:
Starbeamrainbowlabs 2021-09-03 01:12:49 +01:00
parent 4dda12d195
commit 54166c9b79
Signed by: sbrl
GPG Key ID: 1BE5172E637709C2
1 changed files with 3 additions and 3 deletions

View File

@ -122,10 +122,10 @@ register_module([
foreach($credits as $thing => $author_details) foreach($credits as $thing => $author_details)
{ {
$credits_html .= " <li>"; $credits_html .= " <li>";
$credits_html .= "<a href='" . $author_details["thing_url"] . "'>$thing</a> by "; $credits_html .= "<a href='" . htmlentities($author_details["thing_url"]) . "'>".htmlentities($thing)."</a> by ";
if(isset($author_details["icon"])) if(isset($author_details["icon"]))
$credits_html .= "<img class='logo small' style='vertical-align: middle;' src='" . $author_details["icon"] . "' /> "; $credits_html .= "<img class='logo small' style='vertical-align: middle;' src='" . htmlentities($author_details["icon"]) . "' /> ";
$credits_html .= "<a href='" . $author_details["author_url"] . "'>" . $author_details["author"] . "</a>"; $credits_html .= "<a href='" . htmlentities($author_details["author_url"]) . "'>" . $author_details["author"] . "</a>";
$credits_html .= "</li>\n"; $credits_html .= "</li>\n";
} }
$credits_html .= "</ul>"; $credits_html .= "</ul>";