Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix XSS Vulnerability #80

Open
wants to merge 1 commit into
base: master
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion bootstrap-shortcodes.php
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
Plugin Name: Bootstrap Shortcodes
Plugin URI: https://github.com/TheWebShop/bootstrap-shortcodes
Description: A simple shortcode generator. Add buttons, columns, toggles and alerts to your theme.
Version: 3.4.0
Version: 3.4.1
Author: Kevin Attfield
Author URI: https://github.com/Sinetheta

Expand Down
2 changes: 1 addition & 1 deletion inc/bs_alert.php
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ function bs_notice( $params, $content=null ) {
'dismissible' => 'true'
), $params ) );
$content = preg_replace( '/<br class="nc".\/>/', '', $content );
$result = '<div class="alert alert-'.$type.($dismissible=='true'? ' alert-dismissible' : '').'">';
$result = '<div class="alert alert-'.esc_attr($type).($dismissible=='true'? ' alert-dismissible' : '').'">';
$result .= $dismissible=='true'? '<button type="button" class="close" data-dismiss="alert" aria-hidden="true">&times;</button>' : '';
$result .= do_shortcode( $content );
$result .= '</div>';
Expand Down
2 changes: 1 addition & 1 deletion inc/bs_buttons.php
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ function bs_buttons( $params, $content=null ) {
), $params ) );

$content = preg_replace( '/<br class="nc".\/>/', '', $content );
$result = '<a class="btn btn-' . $size . ' btn-' . $type . '" href="' . $href . '">' . $value . '</a>';
$result = '<a class="btn btn-' . esc_attr($size) . ' btn-' . esc_attr($type) . '" href="' . esc_url($href) . '">' . esc_attr($value) . '</a>';
return force_balance_tags( $result );
}
add_shortcode( 'bs_button', 'bs_buttons' );
10 changes: 5 additions & 5 deletions inc/bs_collapse.php
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ function bs_collapse( $params, $content=null ){
'id'=>''
), $params ) );
$content = preg_replace( '/<br class="nc".\/>/', '', $content );
$result = '<div class="panel-group" id="' . $id . '">';
$result = '<div class="panel-group" id="' . esc_attr($id) . '">';
$result .= do_shortcode( $content );
$result .= '</div>';
return force_balance_tags( $result );
Expand All @@ -22,14 +22,14 @@ function bs_citem( $params, $content=null ){
), $params ) );
$content = preg_replace( '/<br class="nc".\/>/', '', $content );
$result = '<div class="panel panel-default">';
$result .= ' <div class="panel-heading" role="tab" id="heading_' . $id . '">';
$result .= ' <div class="panel-heading" role="tab" id="heading_' . esc_attr($id) . '">';
$result .= ' <h4 class="panel-title">';
$result .= '<a class="accordion-toggle collapsed" data-toggle="collapse" aria-controls="heading_' . $id . '" data-parent="#' . $parent . '" href="#' . $id . '">';
$result .= $title;
$result .= '<a class="accordion-toggle collapsed" data-toggle="collapse" aria-controls="heading_' . esc_attr($id) . '" data-parent="#' . esc_attr($parent) . '" href="#' . esc_attr($id) . '">';
$result .= esc_attr($title);
$result .= '</a>';
$result .= ' </h4>';
$result .= ' </div>';
$result .= ' <div id="' . $id . '" class="panel-collapse collapse '.($open=='true'? 'in' : '').'" role="tabpanel" aria-labelledby="heading_' . $id . '">';
$result .= ' <div id="' . esc_attr($id) . '" class="panel-collapse collapse '.($open=='true'? 'in' : '').'" role="tabpanel" aria-labelledby="heading_' . esc_attr($id) . '">';
$result .= ' <div class="panel-body">';
$result .= do_shortcode( $content );
$result .= ' </div>';
Expand Down
6 changes: 3 additions & 3 deletions inc/bs_grid.php
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ function bs_row( $params, $content=null ) {
'class' => 'row'
), $params ) );
$content = preg_replace( '/<br class="nc".\/>/', '', $content );
$result = '<div class="' . $class . '">';
$result = '<div class="' . esc_attr($class) . '">';
$result .= do_shortcode( $content );
$result .= '</div>';
return force_balance_tags( $result );
Expand All @@ -17,9 +17,9 @@ function bs_span( $params, $content=null ) {
'class' => 'col-sm-1'
), $params ) );

$result = '<div class="' . $class . '">';
$result = '<div class="' . esc_attr($class) . '">';
$result .= do_shortcode( $content );
$result .= '</div>';
return force_balance_tags( $result );
}
add_shortcode( 'bs_col', 'bs_span' );
add_shortcode( 'bs_col', 'bs_span' );
2 changes: 1 addition & 1 deletion inc/bs_icons.php
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ function bs_icons( $params, $content=null ) {
), $params));

$content = preg_replace( '/<br class="nc".\/>/', '', $content );
$result = '<i class="' . $name . '"></i>';
$result = '<i class="' . esc_attr($name) . '"></i>';
return force_balance_tags( $result );
}
add_shortcode( 'bs_icon', 'bs_icons' );
2 changes: 1 addition & 1 deletion inc/bs_labels.php
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ function bs_labels( $params, $content=null ) {
), $params ) );

$content = preg_replace( '/<br class="nc".\/>/', '', $content );
$result = '<span class="label label-' . $type . '">' . $content . '</span>';
$result = '<span class="label label-' . esc_attr($type) . '">' . $content . '</span>';
return force_balance_tags( $result );
}
add_shortcode( 'bs_label', 'bs_labels' );
8 changes: 4 additions & 4 deletions inc/bs_tabs.php
Original file line number Diff line number Diff line change
Expand Up @@ -40,8 +40,8 @@ function bs_tab( $params, $content=null ) {
), $params ) );
$content = preg_replace( '/<br class="nc".\/>/', '', $content );

$result = '<li class="' . $class . '">';
$result .= '<a data-toggle="tab" href="' . $href . '">' . $title . '</a>';
$result = '<li class="' . esc_attr($class) . '">';
$result .= '<a data-toggle="tab" href="' . esc_url($href) . '">' . esc_attr($title) . '</a>';
$result .= '</li>';
return force_balance_tags( $result );
}
Expand All @@ -56,7 +56,7 @@ function bs_dropdown( $params, $content=null ) {
), $params ) );
$content = preg_replace( '/<br class="nc".\/>/', '', $content );
$result = '<li class="dropdown">';
$result .= '<a class="' . $class . '" id="' . $id . '" class="dropdown-toggle" data-toggle="dropdown">' . $title . '<b class="caret"></b></a>';
$result .= '<a class="' . esc_attr($class) . '" id="' . esc_attr($id) . '" class="dropdown-toggle" data-toggle="dropdown">' . esc_attr($title) . '<b class="caret"></b></a>';
$result .= '<ul class="dropdown-menu">';
$result .= do_shortcode( $content );
$result .= '</ul></li>';
Expand All @@ -80,7 +80,7 @@ function bs_tcontent( $params, $content=null ) {
), $params ) );
$content = preg_replace( '/<br class="nc".\/>/', '', $content );
$class = ($class=='active')? 'active in': '';
$result = '<div class="tab-pane fade ' . $class . '" id=' . $id . '>';
$result = '<div class="tab-pane fade ' . esc_attr($class) . '" id=' . esc_attr($id) . '>';
$result .= do_shortcode( $content );
$result .= '</div>';
return force_balance_tags( $result );
Expand Down
4 changes: 2 additions & 2 deletions inc/bs_well.php
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,9 @@ function bs_well( $params, $content=null ) {
), $params));

$content = preg_replace( '/<br class="nc".\/>/', '', $content );
$result = '<div class="well well-' . $size . '">';
$result = '<div class="well well-' . esc_attr($size) . '">';
$result .= do_shortcode( $content );
$result .= '</div>';
return force_balance_tags( $result );
}
add_shortcode( 'bs_well', 'bs_well' );
add_shortcode( 'bs_well', 'bs_well' );
7 changes: 5 additions & 2 deletions readme.txt
Original file line number Diff line number Diff line change
Expand Up @@ -2,8 +2,8 @@
Contributors: sinetheta, beaurixon, no3x, Designwall Team
Tags: shortcode, shortcodes, bootstrap, buttons, grid, well, responsive, widget
Requires at least: 3.9
Tested up to: 4.3
Stable tag: 3.4.0
Tested up to: 6.2
Stable tag: 3.4.1
License: GNU General Public License v2.0
License URI: http://www.gnu.org/licenses/gpl-2.0.html

Expand Down Expand Up @@ -48,6 +48,9 @@ Please report issues directly to our [Github repository](https://github.com/TheW

== Changelog ==

= 3.4.1 =
* Fix XSS vulnerability (escaping shortcode attributes)

= 3.4.0 =
* Updated icons to 3.3.5
* Added control panel popup for inserting alerts.
Expand Down