From 696670e5d530c25ed5f6debb7f82d93ba338e525 Mon Sep 17 00:00:00 2001
From: savvasha
Date: Fri, 5 Nov 2021 17:56:58 +0200
Subject: [PATCH] Escape output vars from admin meta-boxes (#1)
---
.../class-sp-meta-box-calendar-columns.php | 4 +--
.../class-sp-meta-box-calendar-data.php | 6 ++--
.../class-sp-meta-box-calendar-details.php | 6 ++--
.../class-sp-meta-box-calendar-feeds.php | 4 +--
.../class-sp-meta-box-calendar-format.php | 2 +-
.../class-sp-meta-box-column-details.php | 6 ++--
.../meta-boxes/class-sp-meta-box-equation.php | 8 ++---
.../class-sp-meta-box-event-format.php | 2 +-
.../class-sp-meta-box-event-mode.php | 2 +-
.../class-sp-meta-box-event-officials.php | 2 +-
.../class-sp-meta-box-event-performance.php | 32 +++++++++----------
11 files changed, 37 insertions(+), 37 deletions(-)
diff --git a/includes/admin/post-types/meta-boxes/class-sp-meta-box-calendar-columns.php b/includes/admin/post-types/meta-boxes/class-sp-meta-box-calendar-columns.php
index c0ded109..eebcfb7b 100644
--- a/includes/admin/post-types/meta-boxes/class-sp-meta-box-calendar-columns.php
+++ b/includes/admin/post-types/meta-boxes/class-sp-meta-box-calendar-columns.php
@@ -62,8 +62,8 @@ class SP_Meta_Box_Calendar_Columns {
?>
|
- post_title; ?>
+ post_title ); ?>
ID ) . '">' . $team_result . ' ';
endif;
- echo $name . ' ';
+ echo esc_attr( $name ) . ' ';
endif;
endforeach; else:
echo '—';
@@ -241,7 +241,7 @@ class SP_Meta_Box_Calendar_Data {
if ( '' == $day ) {
echo '—';
} else {
- echo $day;
+ echo esc_attr( $day );
}
?>
|
diff --git a/includes/admin/post-types/meta-boxes/class-sp-meta-box-calendar-details.php b/includes/admin/post-types/meta-boxes/class-sp-meta-box-calendar-details.php
index db522044..67764536 100644
--- a/includes/admin/post-types/meta-boxes/class-sp-meta-box-calendar-details.php
+++ b/includes/admin/post-types/meta-boxes/class-sp-meta-box-calendar-details.php
@@ -56,7 +56,7 @@ class SP_Meta_Box_Calendar_Details {
@@ -74,9 +74,9 @@ class SP_Meta_Box_Calendar_Details {
-
+
:
-
+
diff --git a/includes/admin/post-types/meta-boxes/class-sp-meta-box-calendar-feeds.php b/includes/admin/post-types/meta-boxes/class-sp-meta-box-calendar-feeds.php
index 293209f2..5dd3aa40 100644
--- a/includes/admin/post-types/meta-boxes/class-sp-meta-box-calendar-feeds.php
+++ b/includes/admin/post-types/meta-boxes/class-sp-meta-box-calendar-feeds.php
@@ -42,10 +42,10 @@ class SP_Meta_Box_Calendar_Feeds {
?>
-
+
-
+
diff --git a/includes/admin/post-types/meta-boxes/class-sp-meta-box-calendar-format.php b/includes/admin/post-types/meta-boxes/class-sp-meta-box-calendar-format.php
index ad94bcf7..38662710 100644
--- a/includes/admin/post-types/meta-boxes/class-sp-meta-box-calendar-format.php
+++ b/includes/admin/post-types/meta-boxes/class-sp-meta-box-calendar-format.php
@@ -24,7 +24,7 @@ class SP_Meta_Box_Calendar_Format {
?>
formats->calendar as $key => $format ): ?>
- >
+ >
-
-
+
+
-
+
diff --git a/includes/admin/post-types/meta-boxes/class-sp-meta-box-equation.php b/includes/admin/post-types/meta-boxes/class-sp-meta-box-equation.php
index 87f99567..69f65134 100644
--- a/includes/admin/post-types/meta-boxes/class-sp-meta-box-equation.php
+++ b/includes/admin/post-types/meta-boxes/class-sp-meta-box-equation.php
@@ -58,7 +58,7 @@ class SP_Meta_Box_Equation {
endforeach;
// Add operators to options
- $options[ 'Operators' ] = array( '+' => '+', '-' => '−', '*' => '×', '/' => '÷', '(' => '(', ')' => ')' );
+ $options[ 'Operators' ] = array( '+' => '+', '-' => '−', '*' => '×', '/' => '÷', '(' => '(', ')' => ')' );
// Create array of constants
$max = 10;
@@ -83,7 +83,7 @@ class SP_Meta_Box_Equation {
|
$value ): $parts[ $key ] = $value;
- ?>
|
@@ -91,7 +91,7 @@ class SP_Meta_Box_Equation {
-
=
+
=
××
diff --git a/includes/admin/post-types/meta-boxes/class-sp-meta-box-event-format.php b/includes/admin/post-types/meta-boxes/class-sp-meta-box-event-format.php
index 2221c8a1..4f7f25da 100644
--- a/includes/admin/post-types/meta-boxes/class-sp-meta-box-event-format.php
+++ b/includes/admin/post-types/meta-boxes/class-sp-meta-box-event-format.php
@@ -24,7 +24,7 @@ class SP_Meta_Box_Event_Format {
?>
formats->event as $key => $format ): ?>
- >
+ >
__( 'Team vs team', 'sportspress' ), 'player' => __( 'Player vs player', 'sportspress' ) ) as $key => $mode ): ?>
- >
+ >
-
name; ?>
+
name ); ?>
'sp_official',
diff --git a/includes/admin/post-types/meta-boxes/class-sp-meta-box-event-performance.php b/includes/admin/post-types/meta-boxes/class-sp-meta-box-event-performance.php
index 1a6098d0..cc7f842d 100644
--- a/includes/admin/post-types/meta-boxes/class-sp-meta-box-event-performance.php
+++ b/includes/admin/post-types/meta-boxes/class-sp-meta-box-event-performance.php
@@ -233,7 +233,7 @@ class SP_Meta_Box_Event_Performance {
?>
- —
+ —
@@ -322,12 +322,12 @@ class SP_Meta_Box_Event_Performance {
-