Security Bug 1697308: Sanitizing the registration form information

To avoid potential hacking vectors for the site


......@@ -2398,6 +2398,12 @@ function auth_register_submit(Pieform $form, $values) {
global $SESSION;
safe_require('auth', 'internal');
// We need to sanitize the $values to avoid hacking vectors
// There should not be any HTML/JS in the fields so we clean it with htmlpurifier
// Then remove even the safe html tags
foreach ($values as $key => $value) {
$values[$key] = strip_tags(clean_html($value));
$values['key'] = get_random_key();
$values['lang'] = $SESSION->get('lang');
