diff --git a/course/category.php b/course/category.php index ac0811a214dbd..8605b7044a849 100644 --- a/course/category.php +++ b/course/category.php @@ -15,7 +15,7 @@ $moveup = optional_param('moveup', 0, PARAM_INT); $movedown = optional_param('movedown', 0, PARAM_INT); $moveto = optional_param('moveto', 0, PARAM_INT); - $rename = optional_param('rename', '', PARAM_NOTAGS); + $rename = optional_param('rename', '', PARAM_RAW); $resort = optional_param('resort', 0, PARAM_BOOL); $addsubcategory=optional_param('addsubcategory', '', PARAM_NOTAGS); @@ -66,7 +66,7 @@ if (has_capability('moodle/category:update', $context)) { /// Rename the category if requested if (!empty($rename) and confirm_sesskey()) { - $category->name = $rename; + $category->name = stripslashes_safe($rename); if (! set_field("course_categories", "name", $category->name, "id", $category->id)) { notify("An error occurred while renaming the category"); } @@ -478,7 +478,7 @@ echo '
'; echo ''; echo ''; - echo ''; + echo ''; echo ''; echo '
'; echo '
';