summaryrefslogtreecommitdiff
path: root/src/templates/confirm_deletion.php
diff options
context:
space:
mode:
authorDavid T. Sadler <davidtsadler@googlemail.com>2021-11-01 21:24:31 +0000
committerDavid T. Sadler <davidtsadler@googlemail.com>2021-11-01 21:24:31 +0000
commit558959d4d7dcceff000fd5861f2f46451ebbd8a9 (patch)
tree550a4df1072333a4d3da5524d80d34689c6227a2 /src/templates/confirm_deletion.php
parent647395dd6a9152ddb9d298daff21c6a3ada6d80b (diff)
Ensure html is escaped
Diffstat (limited to 'src/templates/confirm_deletion.php')
-rw-r--r--src/templates/confirm_deletion.php2
1 files changed, 1 insertions, 1 deletions
diff --git a/src/templates/confirm_deletion.php b/src/templates/confirm_deletion.php
index 0a800e5..06e133f 100644
--- a/src/templates/confirm_deletion.php
+++ b/src/templates/confirm_deletion.php
@@ -9,7 +9,7 @@
<a href="/">Back</a>
<form action="/delete" method="POST">
<input type="hidden" name="id" value="<?php echo $bookmark->id; ?>"/>
- <?php echo $bookmark->url.' '.$bookmark->title.' '.$bookmark->tag; ?>
+ <?php echo htmlentities($bookmark->url.' '.$bookmark->title.' '.$bookmark->tag); ?>
<button type="submit">Delete</button>
</form>
</body>