瀏覽代碼

Fix description handling

andryyy 8 年之前
父節點
當前提交
d9d2500501
共有 1 個文件被更改,包括 1 次插入1 次删除
  1. 1 1
      data/web/edit.php

+ 1 - 1
data/web/edit.php

@@ -505,7 +505,7 @@ if (isset($_SESSION['mailcow_cc_role']) && ($_SESSION['mailcow_cc_role'] == "adm
 					<div class="form-group">
 						<label class="control-label col-sm-2" for="description"><?=$lang['add']['description'];?></label>
 						<div class="col-sm-10">
-							<input type="text" class="form-control" name="description" id="description" value="<?=$result['description'];?>" required>
+							<input type="text" class="form-control" name="description" id="description" value="<?=htmlspecialchars($result['description'], ENT_QUOTES, 'UTF-8');?>" required>
 						</div>
 					</div>
 					<div class="form-group">