escape category name

This commit is contained in:
Uwe Steinmann 2022-09-21 14:29:39 +02:00
parent dbb9e09070
commit d13bc2a6bb

View File

@ -224,7 +224,7 @@ console.log(params);
if(!$nodocumentformfields || !in_array('categories', $nodocumentformfields)) { if(!$nodocumentformfields || !in_array('categories', $nodocumentformfields)) {
$options = array(); $options = array();
foreach($categories as $category) { foreach($categories as $category) {
$options[] = array($category->getID(), $category->getName()); $options[] = array($category->getID(), htmlspecialchars($category->getName()));
} }
$this->formField( $this->formField(
getMLText("categories"), getMLText("categories"),