Skip to content

Commit f50fc03

Browse files
author
Daniel Neto
committed
Improve URL encoding for pagination links in gallerySection.php
GHSA-hgjh-6wj8-gcgf
1 parent 447691e commit f50fc03

1 file changed

Lines changed: 3 additions & 3 deletions

File tree

plugin/YouTubeAPI/gallerySection.php

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -64,14 +64,14 @@
6464
}
6565
if($_GET['page'] > 1 && !empty($object->prevPageToken)){
6666
?>
67-
<a href="<?php echo "{$global['webSiteRootURL']}page/".($_GET['page']-1)."?pageToken={$object->prevPageToken}&search=".(@$_GET['search']); ?>" class="btn btn-primary btn-sm pull-left">
67+
<a href="<?php echo htmlspecialchars("{$global['webSiteRootURL']}page/".(intval($_GET['page'])-1)."?pageToken=".urlencode($object->prevPageToken)."&search=".urlencode(@$_GET['search']), ENT_QUOTES | ENT_HTML5, 'UTF-8'); ?>" class="btn btn-primary btn-sm pull-left">
6868
<i class="fas fa-angle-double-left"></i> <?php echo __("Previous"); ?>
6969
</a>
7070
<?php
7171
}
7272
if(!empty($object->nextPageToken)){
7373
?>
74-
<a href="<?php echo "{$global['webSiteRootURL']}page/".($_GET['page']+1)."?pageToken={$object->nextPageToken}&search=".(@$_GET['search']); ?>" class="btn btn-primary btn-sm pull-right">
74+
<a href="<?php echo htmlspecialchars("{$global['webSiteRootURL']}page/".(intval($_GET['page'])+1)."?pageToken=".urlencode($object->nextPageToken)."&search=".urlencode(@$_GET['search']), ENT_QUOTES | ENT_HTML5, 'UTF-8'); ?>" class="btn btn-primary btn-sm pull-right">
7575
<?php echo __("Next"); ?> <i class="fas fa-angle-double-right"></i>
7676
</a>
7777
<?php
@@ -80,4 +80,4 @@
8080
</div>
8181
<?php
8282
}
83-
?>
83+
?>

0 commit comments

Comments
 (0)