diff --git a/blocks/html/block_html.php b/blocks/html/block_html.php index b491166d82f..de223ba59ae 100755 --- a/blocks/html/block_html.php +++ b/blocks/html/block_html.php @@ -92,7 +92,11 @@ class block_html extends block_base { } function content_is_trusted() { - return in_array($this->page->context->contextlevel, array(CONTEXT_COURSE, CONTEXT_COURSECAT, CONTEXT_SYSTEM)); + if (!$context = get_context_instance_by_id($this->instance->parentcontextid)) { + return false; + } + //find out if this block is on the profile page - we must not allow any XSS there in case admin uses login-as feature + return ($context->contextlevel != CONTEXT_USER); } /** diff --git a/blocks/html/edit_form.php b/blocks/html/edit_form.php index 089d3458ad6..d1523b1f401 100644 --- a/blocks/html/edit_form.php +++ b/blocks/html/edit_form.php @@ -37,7 +37,11 @@ class block_html_edit_form extends block_edit_form { $mform->addElement('text', 'config_title', get_string('configtitle', 'block_html')); $mform->setType('config_title', PARAM_MULTILANG); - $editoroptions = array('maxfiles' => EDITOR_UNLIMITED_FILES, 'trusttext'=>true, 'context'=>$this->block->context); + // prevent potential XSS on user profile pages + $parentcontext = get_context_instance_by_id($this->block->instance->parentcontextid); + $noclean = ($parentcontext->contextlevel != CONTEXT_USER); + + $editoroptions = array('maxfiles' => EDITOR_UNLIMITED_FILES, 'noclean'=>$noclean, 'context'=>$this->block->context); $mform->addElement('editor', 'config_text', get_string('configcontent', 'block_html'), null, $editoroptions); $mform->setType('config_text', PARAM_RAW); // no XSS prevention here, users must be trusted }