<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE extension SYSTEM "ext-1.0.dtd">

<extension engine="1.0">
	<id>hotfix_13_moderate_xss</id>
	<title>PunBB 1.3 hotfix for XSS exploit in moderate forum.</title>
	<version>1.0</version>
	<description>XSS vulnerability via topic subjects in moderate.php is fixed. Patch by PHPLizardo.</description>
	<author>PunBB Development Team</author>
	<minversion>1.3</minversion>
	<maxtestedon>1.3</maxtestedon>

	<hooks>
		<hook id="mr_topic_actions_moved_row_pre_output,mr_topic_actions_normal_row_pre_output"><![CDATA[
$forum_page['item_body']['info']['select'] = '<li class="info-select"><input id="fld'.$forum_page['fld_count'].'" type="checkbox" name="topics[]" value="'.$cur_topic['id'].'" /> <label for="fld'.$forum_page['fld_count'].'">'.sprintf($lang_forum['Select topic'], forum_htmlencode($cur_topic['subject'])).'</label></li>';
		]]></hook>
	</hooks>
</extension>
