causefx 8 лет назад
Родитель
Сommit
2c217fab0b
1 измененных файлов с 1 добавлено и 0 удалено
  1. 1 0
      chat/refreshmessages.php

+ 1 - 0
chat/refreshmessages.php

@@ -83,6 +83,7 @@ if( $result = $db->query("SELECT * FROM
                                     "<span style=\"font-size: 20px; color: #b77fdb;\"><em>$1</em></span>", $message);
                                     "<span style=\"font-size: 20px; color: #b77fdb;\"><em>$1</em></span>", $message);
             $message = preg_replace("/\*(.*?)\*/",
             $message = preg_replace("/\*(.*?)\*/",
                                     "<span style=\"color: #d89334;\"><strong>$1</strong></span>", $message);
                                     "<span style=\"color: #d89334;\"><strong>$1</strong></span>", $message);
+            $message = htmlspecialchars($message, ENT_QUOTES);
 
 
             // user online avatar
             // user online avatar