| @@ -885,10 +885,19 @@ | ||
| 885 | 885 | if (isset($attrDefaultValues['{payment_total}'])) { |
| 886 | 886 | $attrDefaultValues['{payment_total}'] = '<span class="ff_order_total"></span>'; |
| 887 | 887 | } |
| 888 | 888 | |
| 889 | - // Finally, replace the patterns with the replacements and return the output HTML. | |
| 890 | - return str_replace(array_keys($attrDefaultValues), array_values($attrDefaultValues), $output); | |
| 889 | + // Replace in a single pass. str_replace() with arrays re-scans text an earlier key inserted, | |
| 890 | + // so ?a=javascript{get.b}&b=:alert(1) would assemble a script URL from two escaped values. | |
| 891 | + $replacements = []; | |
| 892 | + foreach ($attrDefaultValues as $pattern => $replacement) { | |
| 893 | + // strtr() returns false on an empty key before PHP 8. | |
| 894 | + if ('' !== (string) $pattern && (is_scalar($replacement) || null === $replacement)) { | |
| 895 | + $replacements[(string) $pattern] = (string) $replacement; | |
| 896 | + } | |
| 897 | + } | |
| 898 | + | |
| 899 | + return strtr($output, $replacements); | |
| 891 | 900 | } |
| 892 | 901 | |
| 893 | 902 | /** |
| 894 | 903 | * Register renderer actions for compiling each element |
| @@ -1376,9 +1385,9 @@ | ||
| 1376 | 1385 | $dateFormat = $atts['date_format']; |
| 1377 | 1386 | } else { |
| 1378 | 1387 | $dateFormat = get_option('date_format') . ' ' . get_option('time_format'); |
| 1379 | 1388 | } |
| 1380 | - return date($dateFormat, strtotime($form->created_at)); | |
| 1389 | + return esc_html(date($dateFormat, strtotime($form->created_at))); | |
| 1381 | 1390 | } elseif ('updated_at' == $atts['info']) { |
| 1382 | 1391 | if ($atts['date_format']) { |
| 1383 | 1392 | $dateFormat = $atts['date_format']; |
| 1384 | 1393 | } else { |
| @@ -1383,9 +1392,9 @@ | ||
| 1383 | 1392 | $dateFormat = $atts['date_format']; |
| 1384 | 1393 | } else { |
| 1385 | 1394 | $dateFormat = get_option('date_format') . ' ' . get_option('time_format'); |
| 1386 | 1395 | } |
| 1387 | - return date($dateFormat, strtotime($form->updated_at)); | |
| 1396 | + return esc_html(date($dateFormat, strtotime($form->updated_at))); | |
| 1388 | 1397 | } elseif ('payment_total' == $atts['info']) { |
| 1389 | 1398 | if (!defined('FLUENTFORMPRO')) { |
| 1390 | 1399 | return ''; |
| 1391 | 1400 | } |