Skip to content

Fix missing escaping in media.php#60

Open
tomjn wants to merge 3 commits intojwplayer:developfrom
tomjn:develop
Open

Fix missing escaping in media.php#60
tomjn wants to merge 3 commits intojwplayer:developfrom
tomjn:develop

Conversation

@tomjn
Copy link
Copy Markdown

@tomjn tomjn commented Aug 17, 2017

During a VIP review I found 4 unescaped variables embedded in double quoted strings, e.g. echo "$variable";. This should be avoided as it's not possible to escape inline this way. This PR fixes those 4 unescaped variables embedded in 2 strings via esc_attr

@tomjn
Copy link
Copy Markdown
Author

tomjn commented Mar 20, 2026

@jwplayer any progress on this? It appears the security improvements still apply

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant