962   $logs = "Order: <pre>" . print_r($order, true) . "</pre>";
 963   $logs .= "Payment Method: <pre>" . print_r($payment_method, true) . "</pre>";
 964   $logs .= "IPN: <pre>" . print_r($ipn, true) . "</pre>";
 965   watchdog("commerce_subscription IPN Process", $logs);
 966 

These require a check_plain. eg

$logs = "Order: <pre>" . check_plain(print_r($order, true)) . "</pre>";
// uzw.

I've not confirmed that this is exploitable.

Comments

instanceofjamie’s picture

Agreed. Again, if I get a patch in the next week or so I'll apply it, if not I'll grab some time to make the change myself.

duaelfr’s picture

Here is a patch using the filter_xss function from drupal core.

duaelfr’s picture

Status: Active » Needs review