From bfa26b8634bbe0a21b65dacea3a4a11371bda45d Mon Sep 17 00:00:00 2001 From: Neil Lathwood Date: Wed, 17 May 2017 20:11:54 +0100 Subject: [PATCH] fix: Revert to using addslashes() for template parsing in alerts (#6661) * fix: Revert to using addslashes() for template parsing in alerts * Update alerts.inc.php --- includes/alerts.inc.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/includes/alerts.inc.php b/includes/alerts.inc.php index c91eff12b0..91819157ad 100644 --- a/includes/alerts.inc.php +++ b/includes/alerts.inc.php @@ -322,7 +322,7 @@ function GetContacts($results) function FormatAlertTpl($obj) { $tpl = $obj["template"]; - $msg = '$ret .= "'.str_replace(array('{else}', '{/if}', '{/foreach}'), array('"; } else { $ret .= "', '"; } $ret .= "', '"; } $ret .= "'), str_replace("'", "\'", $tpl)).'";'; + $msg = '$ret .= "'.str_replace(array('{else}', '{/if}', '{/foreach}'), array('"; } else { $ret .= "', '"; } $ret .= "', '"; } $ret .= "'), addslashes($tpl)).'";'; $parsed = $msg; $s = strlen($msg); $x = $pos = -1;