diff --git a/main/admin/legal_add.php b/main/admin/legal_add.php index b0fd4652ab..3b94f8f9a6 100755 --- a/main/admin/legal_add.php +++ b/main/admin/legal_add.php @@ -1,19 +1,20 @@ -validate()) { $check = Security::check_token('post'); @@ -36,9 +37,8 @@ if( $form->validate()) { } elseif (isset($values['back'])) { $submit ='back'; } - }else { + } else { $submit = $values['send']; - } $default[content]=$content; @@ -97,7 +97,7 @@ if( $form->validate()) { }*/ } $form->setDefaults($default); -//var_dump($term_preview); + if(isset($_POST['send'])) { Security::clear_token(); } @@ -120,8 +120,8 @@ $form->addElement('html',$text); if (isset($_POST['language'])) { //$form->addElement('html_editor', 'content', null, null, array('ToolbarSet' => 'Basic', 'Width' => '100%', 'Height' => '250')); - $form->addElement('static', $_POST['language']); - $form->addElement('hidden', 'language',$_POST['language']); + $form->addElement('static', Security::remove_XSS($_POST['language'])); + $form->addElement('hidden', 'language',Security::remove_XSS($_POST['language'])); $form->add_html_editor('content', get_lang('Content'), true, false, array('ToolbarSet' => 'terms_and_conditions', 'Width' => '100%', 'Height' => '250')); //$form->addElement('textarea', 'content', get_lang('Content'),array('cols'=>'120','rows'=>'10')); $form->addElement('radio', 'type', '', get_lang('HTMLText') ,'0'); @@ -143,15 +143,14 @@ if (isset($_POST['language'])) { $navigator_info = api_get_navigator(); //ie6 fix if ($navigator_info['name']=='Internet Explorer' && $navigator_info['version']=='6') { - - $buttons = '