MDL-21769 fixed input validation
authorPetr Skoda <skodak@moodle.org>
Sun, 7 Mar 2010 15:16:38 +0000 (15:16 +0000)
committerPetr Skoda <skodak@moodle.org>
Sun, 7 Mar 2010 15:16:38 +0000 (15:16 +0000)
blog/edit.php

index 82fd010..d35cb83 100755 (executable)
@@ -87,6 +87,9 @@ if ($id) {
         print_error('notallowedtoedit', 'blog');
     }
     $userid = $entry->userid;
+    $entry->subject      = clean_text($entry->subject);
+    $entry->summary      = clean_text($entry->summary, $entry->format);
+    
 } else {
     if (!has_capability('moodle/blog:create', $sitecontext)) {
         print_error('noentry', 'blog'); // manageentries is not enough for adding