Fixed HTML injection

This commit is contained in:
Marcin Kurczewski 2013-10-13 21:05:20 +02:00
parent 5f3a913629
commit e125ecc1c7

View file

@ -64,7 +64,7 @@
?>
<li>
<form name="search" action="<?php echo \Chibi\UrlHelper::route('post', 'list') ?>" method="get">
<input type="search" name="query" placeholder="Search&hellip;" value="<?php echo isset($this->context->transport->searchQuery) ? $this->context->transport->searchQuery : '' ?>">
<input type="search" name="query" placeholder="Search&hellip;" value="<?php echo isset($this->context->transport->searchQuery) ? htmlspecialchars($this->context->transport->searchQuery) : '' ?>">
</form>
</li>
</ul>