diff options
| author | David T. Sadler <davidtsadler@googlemail.com> | 2021-11-01 21:24:31 +0000 |
|---|---|---|
| committer | David T. Sadler <davidtsadler@googlemail.com> | 2021-11-01 21:24:31 +0000 |
| commit | 558959d4d7dcceff000fd5861f2f46451ebbd8a9 (patch) | |
| tree | 550a4df1072333a4d3da5524d80d34689c6227a2 /src/templates/confirm_deletion.php | |
| parent | 647395dd6a9152ddb9d298daff21c6a3ada6d80b (diff) | |
Ensure html is escaped
Diffstat (limited to 'src/templates/confirm_deletion.php')
| -rw-r--r-- | src/templates/confirm_deletion.php | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/src/templates/confirm_deletion.php b/src/templates/confirm_deletion.php index 0a800e5..06e133f 100644 --- a/src/templates/confirm_deletion.php +++ b/src/templates/confirm_deletion.php @@ -9,7 +9,7 @@ <a href="/">Back</a> <form action="/delete" method="POST"> <input type="hidden" name="id" value="<?php echo $bookmark->id; ?>"/> - <?php echo $bookmark->url.' '.$bookmark->title.' '.$bookmark->tag; ?> + <?php echo htmlentities($bookmark->url.' '.$bookmark->title.' '.$bookmark->tag); ?> <button type="submit">Delete</button> </form> </body> |
