From d3d167affb7f2ac7708e8fe54658df594b6f672c Mon Sep 17 00:00:00 2001 From: czaks Date: Wed, 8 Jul 2015 16:26:58 +0200 Subject: [PATCH] SECURITY: XSS fix for youtube.js/metacafe embed --- inc/config.php | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/inc/config.php b/inc/config.php index 32308bd4..75506645 100644 --- a/inc/config.php +++ b/inc/config.php @@ -1022,7 +1022,7 @@ '' ), array( - '/^https?:\/\/(\w+\.)?metacafe\.com\/watch\/(\d+)\/([a-zA-Z0-9_\-.]+)\/(\?.+)?$/i', + '/^https?:\/\/(\w+\.)?metacafe\.com\/watch\/(\d+)\/([a-zA-Z0-9_\-.]+)\/(\?[^\'"<>]+)?$/i', '
' ), array( @@ -1665,6 +1665,6 @@ // Youtube.js embed HTML code $config['youtube_js_html'] = '
'. - ''. + ''. ''. '
';