From 3817a3dbba2ca950f166d5fb4d79860c4117263d Mon Sep 17 00:00:00 2001 From: Brian Wolff Date: Sun, 15 Nov 2015 21:23:38 -0500 Subject: [PATCH] SECURITY: Fix escaping of description field Bug: T118682 Change-Id: Ic40d258964d526a66431f18d2d7f0a6ad2eca111 --- TemplateDataBlob.php | 2 +- extension.json | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/TemplateDataBlob.php b/TemplateDataBlob.php index e06bcd8e..0b406ccc 100644 --- a/TemplateDataBlob.php +++ b/TemplateDataBlob.php @@ -830,7 +830,7 @@ class TemplateDataBlob { 'mw-templatedata-doc-muted' => ( $paramObj->description === null ) ] ], - Html::rawElement( 'p', [], + Html::element( 'p', [], $paramObj->description !== null ? $paramObj->description : wfMessage( 'templatedata-doc-param-desc-empty' )->inLanguage( $lang )->text() diff --git a/extension.json b/extension.json index e8be2908..010fdfc2 100644 --- a/extension.json +++ b/extension.json @@ -1,6 +1,6 @@ { "name": "TemplateData", - "version": "0.1.1", + "version": "0.1.2", "author": [ "Timo Tijhof", "Moriel Schottlender",