Skip to content

Commit e06edde

Browse files
ylafontripu
authored andcommitted
escape error messages
1 parent b1d59c9 commit e06edde

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

src/class.Message.php

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,7 @@ class Message
3939
private function __construct($type, $message, $title='') {
4040
$this->type = $type;
4141
$this->title = $title;
42-
$this->message = $message;
42+
$this->message = htmlspecialchars($message, ENT_QUOTES | ENT_HTML5);
4343
}
4444

4545
static function addMessage($type, $message, $title='') {
@@ -49,4 +49,4 @@ static function addMessage($type, $message, $title='') {
4949
static function clearMessages() {
5050
Message::$messages = array();
5151
}
52-
}
52+
}

0 commit comments

Comments
 (0)