Page MenuHomePhabricator

Raw HTML messages in PageAssessments
Closed, ResolvedPublic

Description

in src/SpecialPage:

			. Html::rawElement( 'th', [], wfMessage( 'pageassessments-importance' )->text() )
			. Html::rawElement( 'th', [], wfMessage( 'pageassessments-class' )->text() )

Also should use $this->msg() instead of wfMessage.

<checkstyle version="6.5">
  <file name="./src/SpecialPage.php">
    <error line="153" severity="warning" message="Calling method \OutputPage::addHTML() in \MediaWiki\Extension\PageAssessments\SpecialPage::outputResults that outputs using tainted argument $html. (Caused by: ./src/SpecialPage.php +132; ./src/SpecialPage.php +146; ./src/SpecialPage.php +151; ./src/SpecialPage.php +153)" source="SecurityCheck-XSS"/>
  </file>
</checkstyle>