From: Jan Schneider Date: Fri, 9 Oct 2009 16:11:52 +0000 (+0200) Subject: Escape event titles in year view. X-Git-Url: https://git.internetallee.de/?a=commitdiff_plain;h=c4fcef52ce22c028b0ec2b80a7f2cbff775b7caa;p=horde.git Escape event titles in year view. --- diff --git a/kronolith/js/kronolith.js b/kronolith/js/kronolith.js index 39147bf0c..332373243 100644 --- a/kronolith/js/kronolith.js +++ b/kronolith/js/kronolith.js @@ -925,7 +925,7 @@ KronolithCore = { } else { title += event.value.start.toString('t') + '-' + event.value.end.toString('t'); } - title += ': ' + event.value.t; + title += ': ' + event.value.t.escapeHTML(); if (event.value.x == Kronolith.conf.status.tentative || event.value.x == Kronolith.conf.status.confirmed) { busy = true;