diff --git a/blocks/html/block_html.php b/blocks/html/block_html.php
index b491166d82f..de223ba59ae 100755
--- a/blocks/html/block_html.php
+++ b/blocks/html/block_html.php
@@ -92,7 +92,11 @@ class block_html extends block_base {
}
function content_is_trusted() {
- return in_array($this->page->context->contextlevel, array(CONTEXT_COURSE, CONTEXT_COURSECAT, CONTEXT_SYSTEM));
+ if (!$context = get_context_instance_by_id($this->instance->parentcontextid)) {
+ return false;
+ }
+ //find out if this block is on the profile page - we must not allow any XSS there in case admin uses login-as feature
+ return ($context->contextlevel != CONTEXT_USER);
}
/**
diff --git a/blocks/html/edit_form.php b/blocks/html/edit_form.php
index 089d3458ad6..d1523b1f401 100644
--- a/blocks/html/edit_form.php
+++ b/blocks/html/edit_form.php
@@ -37,7 +37,11 @@ class block_html_edit_form extends block_edit_form {
$mform->addElement('text', 'config_title', get_string('configtitle', 'block_html'));
$mform->setType('config_title', PARAM_MULTILANG);
- $editoroptions = array('maxfiles' => EDITOR_UNLIMITED_FILES, 'trusttext'=>true, 'context'=>$this->block->context);
+ // prevent potential XSS on user profile pages
+ $parentcontext = get_context_instance_by_id($this->block->instance->parentcontextid);
+ $noclean = ($parentcontext->contextlevel != CONTEXT_USER);
+
+ $editoroptions = array('maxfiles' => EDITOR_UNLIMITED_FILES, 'noclean'=>$noclean, 'context'=>$this->block->context);
$mform->addElement('editor', 'config_text', get_string('configcontent', 'block_html'), null, $editoroptions);
$mform->setType('config_text', PARAM_RAW); // no XSS prevention here, users must be trusted
}