]> git.wh0rd.org - tt-rss.git/commitdiff
properly escape feed error message in headlines toolbar
authorAndrew Dolgov <fox@madoka.volgo-balt.ru>
Sat, 13 Jul 2013 18:14:18 +0000 (22:14 +0400)
committerAndrew Dolgov <fox@madoka.volgo-balt.ru>
Sat, 13 Jul 2013 18:14:18 +0000 (22:14 +0400)
classes/feeds.php

index 4cace8d5c9aac54840c0b22ba8db1679d9eea799..def24521a80cf7d2adbbe1aa0dd080503b0ca9b1 100644 (file)
@@ -63,7 +63,8 @@ class Feeds extends Handler_Protected {
                                truncate_string($feed_title,30)."</a>";
 
                        if ($error) {
-                               $reply .= "&nbsp;<img title='$error' src='images/error.png' alt='error' class=\"noborder\" style=\"vertical-align : middle\">";
+                               $error = htmlspecialchars($error);
+                               $reply .= "&nbsp;<img title=\"$error\" src='images/error.png' alt='error' class=\"noborder\" style=\"vertical-align : middle\">";
                        }
 
                } else {