@@ -194,7 +194,7 @@ KronolithCore = {
194194 . insert ( message ) ;
195195 if ( alarm . params && alarm . params . notify &&
196196 alarm . params . notify . subtitle ) {
197- message . insert ( new Element ( 'br' ) ) . insert ( alarm . params . notify . subtitle ) ;
197+ message . insert ( new Element ( 'br' ) ) . insert ( alarm . params . notify . subtitle . escapeHTML ( ) ) ;
198198 }
199199 if ( alarm . user ) {
200200 var select = '<select>' ;
@@ -811,7 +811,7 @@ KronolithCore = {
811811 return this . setTitle ( Kronolith . text . agenda + ' ' + dates [ 0 ] . toString ( Kronolith . conf . date_format ) + ' - ' + dates [ 1 ] . toString ( Kronolith . conf . date_format ) ) ;
812812
813813 case 'search' :
814- return this . setTitle ( Kronolith . text . searching . interpolate ( { term : data } ) ) ;
814+ return this . setTitle ( Kronolith . text . searching . interpolate ( { term : data } ) ) . escapeHTML ( ) ;
815815 }
816816 } ,
817817
@@ -2494,7 +2494,7 @@ KronolithCore = {
24942494
24952495 if ( ! Object . isUndefined ( task . value . sd ) ) {
24962496 col . insert ( new Element ( 'span' , { className : 'kronolithSeparator' } ) . update ( ' · ' ) ) ;
2497- col . insert ( new Element ( 'span' , { className : 'kronolithInfo' } ) . update ( task . value . sd ) ) ;
2497+ col . insert ( new Element ( 'span' , { className : 'kronolithInfo' } ) . update ( task . value . sd . escapeHTML ( ) ) ) ;
24982498 }
24992499
25002500 row . insert ( col . show ( ) ) ;
@@ -2988,7 +2988,7 @@ KronolithCore = {
29882988 $ ( 'kronolithCalendarholidayDriver' ) . insert (
29892989 new Element ( 'option' , { value : calendar . name } )
29902990 . setStyle ( { color : calendar . fg , backgroundColor : calendar . bg } )
2991- . insert ( calendar . name )
2991+ . insert ( calendar . name . escapeHTML ( ) )
29922992 ) ;
29932993 } ) ;
29942994 break ;
@@ -5329,7 +5329,7 @@ KronolithCore = {
53295329 $ ( 'kronolithEventId' ) . setValue ( ev . id ) ;
53305330 $ ( 'kronolithEventCalendar' ) . setValue ( ev . ty + '|' + ev . c ) ;
53315331 $ ( 'kronolithEventTarget' ) . setValue ( ev . ty + '|' + ev . c ) ;
5332- $ ( 'kronolithEventTargetRO' ) . update ( Kronolith . conf . calendars [ ev . ty ] [ ev . c ] . name ) ;
5332+ $ ( 'kronolithEventTargetRO' ) . update ( Kronolith . conf . calendars [ ev . ty ] [ ev . c ] . name . escapeHTML ( ) ) ;
53335333 $ ( 'kronolithEventTitle' ) . setValue ( ev . t ) ;
53345334 $ ( 'kronolithEventLocation' ) . setValue ( ev . l ) ;
53355335 if ( ev . l && Kronolith . conf . maps . driver ) {
0 commit comments