From e48bda29143bd1a83001780b4a78e483822d985c Mon Sep 17 00:00:00 2001 From: omer citak Date: Thu, 19 Jul 2018 01:20:51 +0300 Subject: [PATCH] fix XSS vulnerability details: https://github.com/symfony/symfony/issues/27987 --- ExceptionHandler.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/ExceptionHandler.php b/ExceptionHandler.php index 8fedc1b..101f3f4 100644 --- a/ExceptionHandler.php +++ b/ExceptionHandler.php @@ -398,7 +398,7 @@ private function formatArgs(array $args) $formattedValue = str_replace("\n", '', var_export($this->escapeHtml((string) $item[1]), true)); } - $result[] = is_int($key) ? $formattedValue : sprintf("'%s' => %s", $key, $formattedValue); + $result[] = is_int($key) ? $formattedValue : sprintf("'%s' => %s", $this->escapeHtml($key), $formattedValue); } return implode(', ', $result);