correct description sanitizing for text escape strategy
Guite committed Sep 18, 2021
1 parent 0171d4f commit a91ad18
2 changes: 1 addition & 1 deletion Twig/TwigExtension.php
Expand Up @@ -202,7 +202,7 @@ public function escapeDescription($entity)
case 'raw':
return $description;
case 'text':
return nl2br(htmlentities($description));
return nl2br(htmlspecialchars($description));
case 'markdown':
return $this->markdownExtra->transform($description);
