Escape the error message

* This commit prevents a possible reflected XSS
isekai
Robbie Paul 8 years ago
parent 672d7292e2
commit 82162ec753

@ -441,7 +441,7 @@ class OpenID_Connect_Generic_Client_Wrapper {
// you did great, have a cookie! // you did great, have a cookie!
$this->issue_token_refresh_info_cookie( $user->ID, $token_response ); $this->issue_token_refresh_info_cookie( $user->ID, $token_response );
wp_set_auth_cookie( $user->ID, FALSE ); wp_set_auth_cookie( $user->ID, FALSE );
do_action( 'wp_login', $user->user_login, $user ); do_action( 'wp_login', $user->user_login, $user );
} }
/** /**

@ -113,7 +113,7 @@ class OpenID_Connect_Generic_Login_Form {
?> ?>
<div id="login_error"> <div id="login_error">
<strong><?php _e( 'ERROR'); ?>: </strong> <strong><?php _e( 'ERROR'); ?>: </strong>
<?php print $error_message; ?> <?php print esc_html($error_message); ?>
</div> </div>
<?php <?php
return ob_get_clean(); return ob_get_clean();

Loading…
Cancel
Save