| @@ -4,9 +4,9 @@ | ||
| 4 | 4 | * |
| 5 | 5 | * This class handles the AJAX request to edit the curriculum of a course. |
| 6 | 6 | * |
| 7 | 7 | * @since 4.2.9 |
| 8 | - * @version 1.0.0 | |
| 8 | + * @version 1.0.2 | |
| 9 | 9 | */ |
| 10 | 10 | |
| 11 | 11 | namespace LearnPress\Ajax; |
| 12 | 12 | |
| @@ -57,8 +57,10 @@ | ||
| 57 | 57 | * Update question title. |
| 58 | 58 | * |
| 59 | 59 | * JS file edit-quiz.js: function updateQuestionTitle call this method. |
| 60 | 60 | * |
| 61 | + * @since 4.2.9 | |
| 62 | + * @version 1.0.1 | |
| 61 | 63 | */ |
| 62 | 64 | public static function update_question() { |
| 63 | 65 | $response = new LP_REST_Response(); |
| 64 | 66 | |
| @@ -89,20 +91,25 @@ | ||
| 89 | 91 | $questionPostModel->post_content = $question_description; |
| 90 | 92 | } |
| 91 | 93 | |
| 92 | 94 | if ( false !== $question_hint ) { |
| 95 | + $question_hint = Template::sanitize_html_content( $question_hint ); | |
| 93 | 96 | $questionPostModel->save_meta_value_by_key( QuestionPostModel::META_KEY_HINT, $question_hint ); |
| 94 | 97 | } |
| 95 | 98 | |
| 96 | 99 | if ( false !== $question_explanation ) { |
| 100 | + $question_explanation = Template::sanitize_html_content( $question_explanation ); | |
| 97 | 101 | $questionPostModel->save_meta_value_by_key( QuestionPostModel::META_KEY_EXPLANATION, $question_explanation ); |
| 98 | 102 | } |
| 99 | 103 | |
| 100 | 104 | if ( false !== $question_mark ) { |
| 105 | + $question_mark = (float) $question_mark; | |
| 101 | 106 | $questionPostModel->save_meta_value_by_key( QuestionPostModel::META_KEY_MARK, $question_mark ); |
| 102 | 107 | } |
| 103 | 108 | |
| 104 | 109 | if ( false !== $question_type ) { |
| 110 | + $question_type = LP_Helper::sanitize_params_submitted( $question_type, 'key' ); | |
| 111 | + | |
| 105 | 112 | if ( ! in_array( $question_type, array_keys( QuestionPostModel::get_types() ), true ) ) { |
| 106 | 113 | throw new Exception( __( 'Invalid question type', 'learnpress' ) ); |
| 107 | 114 | } |
| 108 | 115 | |