Explorar o código

Update refreshmessages.php

causefx %!s(int64=8) %!d(string=hai) anos
pai
achega
2c217fab0b
Modificáronse 1 ficheiros con 1 adicións e 0 borrados
  1. 1 0
      chat/refreshmessages.php

+ 1 - 0
chat/refreshmessages.php

@@ -83,6 +83,7 @@ if( $result = $db->query("SELECT * FROM
                                     "<span style=\"font-size: 20px; color: #b77fdb;\"><em>$1</em></span>", $message);
             $message = preg_replace("/\*(.*?)\*/",
                                     "<span style=\"color: #d89334;\"><strong>$1</strong></span>", $message);
+            $message = htmlspecialchars($message, ENT_QUOTES);
 
             // user online avatar