aboutsummaryrefslogtreecommitdiff
path: root/mod/blog/actions/blog/save.php
diff options
context:
space:
mode:
authorSteve Clay <steve@mrclay.org>2012-09-09 01:52:09 -0400
committerSteve Clay <steve@mrclay.org>2012-10-10 21:01:56 -0400
commit5efa9426d40326b8d31c152dd2a433076b490308 (patch)
treed94abfb8194e126fbebcbf50b751f9e796e9a9a7 /mod/blog/actions/blog/save.php
parent9ccbd106a87a1742a61cc4df0e9ead921046772a (diff)
downloadelgg-5efa9426d40326b8d31c152dd2a433076b490308.tar.gz
elgg-5efa9426d40326b8d31c152dd2a433076b490308.tar.bz2
Fixes #4593: All titles are HTML-escaped plain text
Diffstat (limited to 'mod/blog/actions/blog/save.php')
-rw-r--r--mod/blog/actions/blog/save.php6
1 files changed, 5 insertions, 1 deletions
diff --git a/mod/blog/actions/blog/save.php b/mod/blog/actions/blog/save.php
index 048bc00be..070c96398 100644
--- a/mod/blog/actions/blog/save.php
+++ b/mod/blog/actions/blog/save.php
@@ -57,7 +57,11 @@ $required = array('title', 'description');
// load from POST and do sanity and access checking
foreach ($values as $name => $default) {
- $value = get_input($name, $default);
+ if ($name === 'title') {
+ $value = htmlspecialchars(get_input('title', $default, false), ENT_QUOTES, 'UTF-8');
+ } else {
+ $value = get_input($name, $default);
+ }
if (in_array($name, $required) && empty($value)) {
$error = elgg_echo("blog:error:missing:$name");