diff options
author | Steve Clay <steve@mrclay.org> | 2012-10-10 18:22:31 -0700 |
---|---|---|
committer | Steve Clay <steve@mrclay.org> | 2012-10-10 18:22:31 -0700 |
commit | d134beadb79fcc90a75bda8bbcbfb9987b27470c (patch) | |
tree | 3228eb49db250d8d1a5a0b36eb58c7051b4d8bbb /mod/groups/actions/discussion/save.php | |
parent | ec68ded7bc64e64d27f9c78efdfa6a7d3d25d14e (diff) | |
parent | 5efa9426d40326b8d31c152dd2a433076b490308 (diff) | |
download | elgg-d134beadb79fcc90a75bda8bbcbfb9987b27470c.tar.gz elgg-d134beadb79fcc90a75bda8bbcbfb9987b27470c.tar.bz2 |
Merge pull request #381 from mrclay/4593-plaintext-titles
Fixes #4593: All titles are HTML-escaped plain text
Diffstat (limited to 'mod/groups/actions/discussion/save.php')
-rw-r--r-- | mod/groups/actions/discussion/save.php | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/mod/groups/actions/discussion/save.php b/mod/groups/actions/discussion/save.php index de4afadfb..b3e9da654 100644 --- a/mod/groups/actions/discussion/save.php +++ b/mod/groups/actions/discussion/save.php @@ -4,7 +4,7 @@ */ // Get variables -$title = get_input("title"); +$title = htmlspecialchars(get_input('title', '', false), ENT_QUOTES, 'UTF-8'); $desc = get_input("description"); $status = get_input("status"); $access_id = (int) get_input("access_id"); |