From 12d17734f62ff83a5fd2d82c69c617c3f0d9008d Mon Sep 17 00:00:00 2001 From: Andrew Dolgov Date: Sat, 13 Jul 2013 22:14:18 +0400 Subject: [PATCH] properly escape feed error message in headlines toolbar --- classes/feeds.php | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/classes/feeds.php b/classes/feeds.php index 4cace8d5..def24521 100644 --- a/classes/feeds.php +++ b/classes/feeds.php @@ -63,7 +63,8 @@ class Feeds extends Handler_Protected { truncate_string($feed_title,30).""; if ($error) { - $reply .= " error"; + $error = htmlspecialchars($error); + $reply .= " error"; } } else {