From 54eeca28e811c7a82e9c7d0973b60e25346721ce Mon Sep 17 00:00:00 2001 From: savvasha Date: Sat, 6 Nov 2021 08:59:30 +0200 Subject: [PATCH] Escape output vars from admin meta-boxes (#3) --- .../class-sp-meta-box-player-statistics.php | 16 +++++++-------- .../class-sp-meta-box-result-details.php | 6 +++--- .../class-sp-meta-box-spec-details.php | 4 ++-- .../class-sp-meta-box-staff-details.php | 4 ++-- .../class-sp-meta-box-statistic-details.php | 6 +++--- .../class-sp-meta-box-table-data.php | 20 +++++++++---------- .../class-sp-meta-box-table-details.php | 6 +++--- .../class-sp-meta-box-table-format.php | 2 +- .../class-sp-meta-box-table-mode.php | 2 +- .../class-sp-meta-box-team-columns.php | 13 +++++++----- .../class-sp-meta-box-team-lists.php | 2 +- .../class-sp-meta-box-team-staff.php | 2 +- .../class-sp-meta-box-team-tables.php | 2 +- 13 files changed, 44 insertions(+), 41 deletions(-) diff --git a/includes/admin/post-types/meta-boxes/class-sp-meta-box-player-statistics.php b/includes/admin/post-types/meta-boxes/class-sp-meta-box-player-statistics.php index efa78652..819793bd 100644 --- a/includes/admin/post-types/meta-boxes/class-sp-meta-box-player-statistics.php +++ b/includes/admin/post-types/meta-boxes/class-sp-meta-box-player-statistics.php @@ -35,7 +35,7 @@ class SP_Meta_Box_Player_Statistics { $i = 0; foreach ( $leagues as $league ): ?> -

name; ?>

+

name ); ?>

data( $league->term_id, true ); self::table( $post->ID, $league->term_id, $columns, $data, $placeholders, $merged, $seasons_teams, $has_checkboxes && $i == 0, true, $formats, $total_types ); @@ -62,7 +62,7 @@ class SP_Meta_Box_Player_Statistics { $i = 0; foreach ( $leagues as $league ): ?> -

name; ?> —

+

name ); ?> —

data( $league->term_id, true, $section_id ); self::table( $post->ID, $league->term_id, $columns, $data, $placeholders, $merged, $seasons_teams, $has_checkboxes && $i == 0 && $s == 0, $s == 0, $formats, $total_types ); @@ -70,7 +70,7 @@ class SP_Meta_Box_Player_Statistics { endforeach; if ( $show_career_totals ) { ?> -

+

data( 0, true, $section_id ); self::table( $post->ID, 0, $columns, $data, $placeholders, $merged, $seasons_teams, $has_checkboxes && $i == 0 && $s == 0, $s == 0, $formats, $total_types ); @@ -108,7 +108,7 @@ class SP_Meta_Box_Player_Statistics { $label ): if ( $key == 'team' ) continue; ?> - + @@ -135,7 +135,7 @@ class SP_Meta_Box_Player_Statistics { } if ( $readonly ) { - echo $value ? $value : $placeholder; + echo $value ? esc_attr( $value ) : esc_attr( $placeholder ); } else { if ( 'time' === sp_array_value( $formats, $column, 'number' ) ) { echo ''; @@ -162,8 +162,8 @@ class SP_Meta_Box_Player_Statistics {