properly escape feed error message in headlines toolbar

master
Andrew Dolgov 11 years ago
parent 7a7a0dc2dd
commit 12d17734f6

@ -63,7 +63,8 @@ class Feeds extends Handler_Protected {
truncate_string($feed_title,30)."</a>"; truncate_string($feed_title,30)."</a>";
if ($error) { if ($error) {
$reply .= "&nbsp;<img title='$error' src='images/error.png' alt='error' class=\"noborder\" style=\"vertical-align : middle\">"; $error = htmlspecialchars($error);
$reply .= "&nbsp;<img title=\"$error\" src='images/error.png' alt='error' class=\"noborder\" style=\"vertical-align : middle\">";
} }
} else { } else {

Loading…
Cancel
Save