aboutsummaryrefslogtreecommitdiff
path: root/mod/groups/actions/groups/edit.php
diff options
context:
space:
mode:
authorSteve Clay <steve@mrclay.org>2012-09-09 01:52:09 -0400
committerSteve Clay <steve@mrclay.org>2012-10-10 21:01:56 -0400
commit5efa9426d40326b8d31c152dd2a433076b490308 (patch)
treed94abfb8194e126fbebcbf50b751f9e796e9a9a7 /mod/groups/actions/groups/edit.php
parent9ccbd106a87a1742a61cc4df0e9ead921046772a (diff)
downloadelgg-5efa9426d40326b8d31c152dd2a433076b490308.tar.gz
elgg-5efa9426d40326b8d31c152dd2a433076b490308.tar.bz2
Fixes #4593: All titles are HTML-escaped plain text
Diffstat (limited to 'mod/groups/actions/groups/edit.php')
-rw-r--r--mod/groups/actions/groups/edit.php3
1 files changed, 1 insertions, 2 deletions
diff --git a/mod/groups/actions/groups/edit.php b/mod/groups/actions/groups/edit.php
index df2464a65..a4169461a 100644
--- a/mod/groups/actions/groups/edit.php
+++ b/mod/groups/actions/groups/edit.php
@@ -33,8 +33,7 @@ foreach ($CONFIG->group as $shortname => $valuetype) {
}
}
-$input['name'] = get_input('name');
-$input['name'] = html_entity_decode($input['name'], ENT_COMPAT, 'UTF-8');
+$input['name'] = htmlspecialchars(get_input('name', '', false), ENT_QUOTES, 'UTF-8');
$user = elgg_get_logged_in_user_entity();