Plugin Directory

Changeset 451246


Ignore:
Timestamp:
10/14/2011 10:57:56 PM (14 years ago)
Author:
Orson Teodoro
Message:

fix signature editing

Location:
forumconverter
Files:
18 added
3 edited

Legend:

Unmodified
Added
Removed
  • forumconverter/trunk/fc-sig-main.php

    r445944 r451246  
    8787        else if (strstr($curl, 'user-edit.php'))
    8888        {
    89             $id = addslashes($_GET['user_id']);
     89            $id = addslashes($_REQUEST['user_id']);
    9090        }
    9191        $sig = $wpdb->get_var('SELECT meta_value FROM '.$wpdb->prefix.'usermeta WHERE user_id='.$id.' AND meta_key="bbp_signature"');
    92         $c = explode('/',plugin_basename(__FILE__));
    93         $plugin_folder = $c[0];
    94         $update_url = plugins_url().'/'.$plugin_folder.'/fc-sig-update.php';
    9592        $sig = str_replace(array("\r\n", "\n"), '\n', $sig);
    96         $sig = wp_kses($sig);
     93        $sig = wp_kses($sig, array('a' => array('href'=>array()), 'font' => array('color'=>array(), 'size'=>array(), 'face'=>array()), 'br' => array(), 'img'=>array('src'=>array(),'alt'=>array(),'class'=>array(),'style'=>array())));
    9794       
    9895        echo <<<SIGUI2
     
    107104            '   </tbody>' +
    108105            '</table>' +
     106            '<input type="hidden" name="bbp_sig_target" value="{$id}" />' +
    109107            '';
    110108            jQuery(".submit").before(out);
     
    159157
    160158    $user = wp_get_current_user();
    161     $id = $user->ID;
     159    if (isset($_REQUEST['bbp_sig_target']))
     160        $id = addslashes($_REQUEST['bbp_sig_target']);
     161    else
     162        $id = $user->ID;
    162163    $sig = addslashes($_POST['sig']);
    163164
  • forumconverter/trunk/fc-sig-update.php

    r445944 r451246  
    1515    Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA  02110-1301  USA
    1616*/
     17
     18    //this is for the ajax update from buddypress
    1719
    1820    require('../../../wp-load.php');
  • forumconverter/trunk/readme.txt

    r445951 r451246  
    55Requires at least: 3.2.1
    66Tested up to: 3.2.1
    7 Stable tag: 1.12
     7Stable tag: 1.13
    88
    99Migrates a phpBB forum into a bbPress forum.
     
    131131
    132132== Upgrade Notice ==
     133= 1.13 =
     134None
     135
    133136= 1.12 =
    134137XSS Security vulnerability.  Please upgrade immediately if your using the signature plugin.  Versions 1.08-1.11 affected.
     
    171174
    172175== Changelog ==
     176= 1.13 =
     177* Bug Fix: Make signatures editing on WordPress backend only make changes to the viewed profile.
     178
    173179= 1.12 =
    174180* Security Fix: Sanitize signatures.
Note: See TracChangeset for help on using the changeset viewer.