| @@ -885,10 +885,19 @@ | ||
| 885 | 885 | if (isset($attrDefaultValues['{payment_total}'])) { |
| 886 | 886 | $attrDefaultValues['{payment_total}'] = '<span class="ff_order_total"></span>'; |
| 887 | 887 | } |
| 888 | 888 | |
| 889 | - // Finally, replace the patterns with the replacements and return the output HTML. | |
| 890 | - return str_replace(array_keys($attrDefaultValues), array_values($attrDefaultValues), $output); | |
| 889 | + // Replace in a single pass. str_replace() with arrays re-scans text an earlier key inserted, | |
| 890 | + // so ?a=javascript{get.b}&b=:alert(1) would assemble a script URL from two escaped values. | |
| 891 | + $replacements = []; | |
| 892 | + foreach ($attrDefaultValues as $pattern => $replacement) { | |
| 893 | + // strtr() returns false on an empty key before PHP 8. | |
| 894 | + if ('' !== (string) $pattern && (is_scalar($replacement) || null === $replacement)) { | |
| 895 | + $replacements[(string) $pattern] = (string) $replacement; | |
| 896 | + } | |
| 897 | + } | |
| 898 | + | |
| 899 | + return strtr($output, $replacements); | |
| 891 | 900 | } |
| 892 | 901 | |
| 893 | 902 | /** |
| 894 | 903 | * Register renderer actions for compiling each element |
| @@ -1376,9 +1385,9 @@ | ||
| 1376 | 1385 | $dateFormat = $atts['date_format']; |
| 1377 | 1386 | } else { |
| 1378 | 1387 | $dateFormat = get_option('date_format') . ' ' . get_option('time_format'); |
| 1379 | 1388 | } |
| 1380 | - return date($dateFormat, strtotime($form->created_at)); | |
| 1389 | + return esc_html(date($dateFormat, strtotime($form->created_at))); | |
| 1381 | 1390 | } elseif ('updated_at' == $atts['info']) { |
| 1382 | 1391 | if ($atts['date_format']) { |
| 1383 | 1392 | $dateFormat = $atts['date_format']; |
| 1384 | 1393 | } else { |
| @@ -1383,9 +1392,9 @@ | ||
| 1383 | 1392 | $dateFormat = $atts['date_format']; |
| 1384 | 1393 | } else { |
| 1385 | 1394 | $dateFormat = get_option('date_format') . ' ' . get_option('time_format'); |
| 1386 | 1395 | } |
| 1387 | - return date($dateFormat, strtotime($form->updated_at)); | |
| 1396 | + return esc_html(date($dateFormat, strtotime($form->updated_at))); | |
| 1388 | 1397 | } elseif ('payment_total' == $atts['info']) { |
| 1389 | 1398 | if (!defined('FLUENTFORMPRO')) { |
| 1390 | 1399 | return ''; |
| 1391 | 1400 | } |
| @@ -1448,17 +1457,19 @@ | ||
| 1448 | 1457 | $atts = shortcode_atts([ |
| 1449 | 1458 | 'param' => '', |
| 1450 | 1459 | ], $atts); |
| 1451 | 1460 | |
| 1461 | + if ('' === $atts['param']) { | |
| 1462 | + return ''; | |
| 1463 | + } | |
| 1464 | + | |
| 1452 | 1465 | $value = $this->app->request->get($atts['param']); |
| 1453 | 1466 | |
| 1454 | - if ($atts['param'] && $value) { | |
| 1455 | - if (is_array($value)) { | |
| 1456 | - return implode(', ', $value); | |
| 1457 | - } | |
| 1458 | - return esc_html($value); | |
| 1467 | + if (null === $value || '' === $value) { | |
| 1468 | + return ''; | |
| 1459 | 1469 | } |
| 1460 | - return ''; | |
| 1470 | + | |
| 1471 | + return esc_html(Helper::flattenRequestValue($value)); | |
| 1461 | 1472 | }); |
| 1462 | 1473 | |
| 1463 | 1474 | $this->app->addShortcode('ff_entry',function($atts){ |
| 1464 | 1475 | ob_start(); |