diff options
author | Steve Clay <steve@mrclay.org> | 2012-09-09 01:52:09 -0400 |
---|---|---|
committer | Steve Clay <steve@mrclay.org> | 2012-10-10 21:01:56 -0400 |
commit | 5efa9426d40326b8d31c152dd2a433076b490308 (patch) | |
tree | d94abfb8194e126fbebcbf50b751f9e796e9a9a7 /mod/groups | |
parent | 9ccbd106a87a1742a61cc4df0e9ead921046772a (diff) | |
download | elgg-5efa9426d40326b8d31c152dd2a433076b490308.tar.gz elgg-5efa9426d40326b8d31c152dd2a433076b490308.tar.bz2 |
Fixes #4593: All titles are HTML-escaped plain text
Diffstat (limited to 'mod/groups')
-rw-r--r-- | mod/groups/actions/discussion/save.php | 2 | ||||
-rw-r--r-- | mod/groups/actions/groups/edit.php | 3 |
2 files changed, 2 insertions, 3 deletions
diff --git a/mod/groups/actions/discussion/save.php b/mod/groups/actions/discussion/save.php index de4afadfb..b3e9da654 100644 --- a/mod/groups/actions/discussion/save.php +++ b/mod/groups/actions/discussion/save.php @@ -4,7 +4,7 @@ */ // Get variables -$title = get_input("title"); +$title = htmlspecialchars(get_input('title', '', false), ENT_QUOTES, 'UTF-8'); $desc = get_input("description"); $status = get_input("status"); $access_id = (int) get_input("access_id"); diff --git a/mod/groups/actions/groups/edit.php b/mod/groups/actions/groups/edit.php index df2464a65..a4169461a 100644 --- a/mod/groups/actions/groups/edit.php +++ b/mod/groups/actions/groups/edit.php @@ -33,8 +33,7 @@ foreach ($CONFIG->group as $shortname => $valuetype) { } } -$input['name'] = get_input('name'); -$input['name'] = html_entity_decode($input['name'], ENT_COMPAT, 'UTF-8'); +$input['name'] = htmlspecialchars(get_input('name', '', false), ENT_QUOTES, 'UTF-8'); $user = elgg_get_logged_in_user_entity(); |