Permalink
Browse files

Security - Fix possible XSS attack vector using teacher role - report…

…ed by Javier Bloem
  • Loading branch information...
ywarnier committed May 6, 2014
1 parent 4634c58 commit 94706d7f99f7cb563c2a4f201c016caf7589fce1
Showing with 1 addition and 0 deletions.
  1. +1 −0 main/inc/lib/banner.lib.php
@@ -484,6 +484,7 @@ function return_breadcrumb($interbreadcrumb, $language_file, $nameTools)
if (!empty($_course) && !isset($_GET['hide_course_breadcrumb'])) {
$navigation_item['url'] = $web_course_path . $_course['path'].'/index.php'.(!empty($session_id) ? '?id_session='.$session_id : '');
$_course['name'] = api_htmlentities($_course['name']);
$course_title = cut($_course['name'], MAX_LENGTH_BREADCRUMB);
switch (api_get_setting('breadcrumbs_course_homepage')) {

0 comments on commit 94706d7

Please sign in to comment.