From 09336b0ff0e0a04aa0c97c5975651af4769d2459 Mon Sep 17 00:00:00 2001 From: Thorsten Rinne Date: Fri, 1 Mar 2024 18:41:57 +0100 Subject: [PATCH] fix: added missing conversion to HTML entities --- phpmyfaq/admin/user.php | 4 ++-- phpmyfaq/ucp.php | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/phpmyfaq/admin/user.php b/phpmyfaq/admin/user.php index 3e33b56fd4..4469ef7a54 100755 --- a/phpmyfaq/admin/user.php +++ b/phpmyfaq/admin/user.php @@ -573,8 +573,8 @@ class="form-check-input permission"> getUserData('display_name')) ?> - - getUserData('email') ?> + + getUserData('email')) ?> getLogin()) ?> diff --git a/phpmyfaq/ucp.php b/phpmyfaq/ucp.php index 614ed599f6..424418f291 100644 --- a/phpmyfaq/ucp.php +++ b/phpmyfaq/ucp.php @@ -78,7 +78,7 @@ 'msgRealName' => Translation::get('ad_user_name'), 'realname' => Strings::htmlentities($user->getUserData('display_name')), 'msgEmail' => Translation::get('msgNewContentMail'), - 'email' => $user->getUserData('email'), + 'email' => Strings::htmlentities($user->getUserData('email')), 'msgIsVisible' => Translation::get('ad_user_data_is_visible'), 'checked' => (int)$user->getUserData('is_visible') === 1 ? 'checked' : '', 'msgPassword' => Translation::get('ad_auth_passwd'),