| @@ -4,9 +4,9 @@ | ||
| 4 | 4 | * |
| 5 | 5 | * This class handles the AJAX request to edit the curriculum of a course. |
| 6 | 6 | * |
| 7 | 7 | * @since 4.2.9 |
| 8 | - * @version 1.0.0 | |
| 8 | + * @version 1.0.2 | |
| 9 | 9 | */ |
| 10 | 10 | |
| 11 | 11 | namespace LearnPress\Ajax; |
| 12 | 12 | |
| @@ -13,8 +13,9 @@ | ||
| 13 | 13 | use Exception; |
| 14 | 14 | use LearnPress\Ajax\AbstractAjax; |
| 15 | 15 | |
| 16 | 16 | use LearnPress\Databases\QuestionAnswersDB; |
| 17 | +use LearnPress\Helpers\Template; | |
| 17 | 18 | use LearnPress\Models\Question\QuestionAnswerModel; |
| 18 | 19 | use LearnPress\Models\Question\QuestionPostFIBModel; |
| 19 | 20 | use LearnPress\Models\Question\QuestionPostModel; |
| 20 | 21 | use LearnPress\Models\Question\QuestionPostMultipleChoiceModel; |
| @@ -56,8 +57,10 @@ | ||
| 56 | 57 | * Update question title. |
| 57 | 58 | * |
| 58 | 59 | * JS file edit-quiz.js: function updateQuestionTitle call this method. |
| 59 | 60 | * |
| 61 | + * @since 4.2.9 | |
| 62 | + * @version 1.0.1 | |
| 60 | 63 | */ |
| 61 | 64 | public static function update_question() { |
| 62 | 65 | $response = new LP_REST_Response(); |
| 63 | 66 | |
| @@ -88,20 +91,25 @@ | ||
| 88 | 91 | $questionPostModel->post_content = $question_description; |
| 89 | 92 | } |
| 90 | 93 | |
| 91 | 94 | if ( false !== $question_hint ) { |
| 95 | + $question_hint = Template::sanitize_html_content( $question_hint ); | |
| 92 | 96 | $questionPostModel->save_meta_value_by_key( QuestionPostModel::META_KEY_HINT, $question_hint ); |
| 93 | 97 | } |
| 94 | 98 | |
| 95 | 99 | if ( false !== $question_explanation ) { |
| 100 | + $question_explanation = Template::sanitize_html_content( $question_explanation ); | |
| 96 | 101 | $questionPostModel->save_meta_value_by_key( QuestionPostModel::META_KEY_EXPLANATION, $question_explanation ); |
| 97 | 102 | } |
| 98 | 103 | |
| 99 | 104 | if ( false !== $question_mark ) { |
| 105 | + $question_mark = (float) $question_mark; | |
| 100 | 106 | $questionPostModel->save_meta_value_by_key( QuestionPostModel::META_KEY_MARK, $question_mark ); |
| 101 | 107 | } |
| 102 | 108 | |
| 103 | 109 | if ( false !== $question_type ) { |
| 110 | + $question_type = LP_Helper::sanitize_params_submitted( $question_type, 'key' ); | |
| 111 | + | |
| 104 | 112 | if ( ! in_array( $question_type, array_keys( QuestionPostModel::get_types() ), true ) ) { |
| 105 | 113 | throw new Exception( __( 'Invalid question type', 'learnpress' ) ); |
| 106 | 114 | } |
| 107 | 115 | |
| @@ -144,9 +152,9 @@ | ||
| 144 | 152 | $response = new LP_REST_Response(); |
| 145 | 153 | |
| 146 | 154 | try { |
| 147 | 155 | $data = self::check_valid(); |
| 148 | - $answer_title = $data['answer_title'] ?? ''; | |
| 156 | + $answer_title = Template::sanitize_html_content( $data['answer_title'] ?? '' ); | |
| 149 | 157 | if ( empty( $answer_title ) ) { |
| 150 | 158 | throw new Exception( __( 'Answer title is required', 'learnpress' ) ); |
| 151 | 159 | } |
| 152 | 160 | |