From 5efa9426d40326b8d31c152dd2a433076b490308 Mon Sep 17 00:00:00 2001 From: Steve Clay Date: Sun, 9 Sep 2012 01:52:09 -0400 Subject: Fixes #4593: All titles are HTML-escaped plain text --- mod/groups/actions/discussion/save.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'mod/groups/actions/discussion/save.php') diff --git a/mod/groups/actions/discussion/save.php b/mod/groups/actions/discussion/save.php index de4afadfb..b3e9da654 100644 --- a/mod/groups/actions/discussion/save.php +++ b/mod/groups/actions/discussion/save.php @@ -4,7 +4,7 @@ */ // Get variables -$title = get_input("title"); +$title = htmlspecialchars(get_input('title', '', false), ENT_QUOTES, 'UTF-8'); $desc = get_input("description"); $status = get_input("status"); $access_id = (int) get_input("access_id"); -- cgit v1.2.3