From bcd2508da610dd967b41f222f045bb390c236eed Mon Sep 17 00:00:00 2001 From: Brian Wolff Date: Sun, 15 Nov 2015 21:23:38 -0500 Subject: [PATCH] SECURITY: Fix escaping of description field Bug: T118682 Change-Id: Ic40d258964d526a66431f18d2d7f0a6ad2eca111 --- TemplateDataBlob.php | 2 +- extension.json | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/TemplateDataBlob.php b/TemplateDataBlob.php index 42e8b826..40b4639c 100644 --- a/TemplateDataBlob.php +++ b/TemplateDataBlob.php @@ -831,7 +831,7 @@ class TemplateDataBlob { 'mw-templatedata-doc-muted' => ( $paramObj->description === null ) ] ], - Html::rawElement( 'p', [], + Html::element( 'p', [], $paramObj->description !== null ? $paramObj->description : wfMessage( 'templatedata-doc-param-desc-empty' )->inLanguage( $lang )->text() diff --git a/extension.json b/extension.json index 5ce0027c..e5d56f8e 100644 --- a/extension.json +++ b/extension.json @@ -1,6 +1,6 @@ { "name": "TemplateData", - "version": "0.1.1", + "version": "0.1.2", "author": [ "Timo Tijhof", "Moriel Schottlender",