Commit 5ba0f704 authored by Côme Chilliet's avatar Côme Chilliet
🚑 fix(msg_dialog) Escape HTML in error dialogs

We’ll need to check there is no error message which actually needs HTML.

issue #5907
parent 60cdb7c6
......@@ -41,12 +41,12 @@
{elseif $i_Type == $smarty.const.INFO_DIALOG || $i_Type == $smarty.const.CONFIRM_DIALOG}
<img src="geticon.php?context=status&amp;icon=dialog-information&amp;size=32" class="center" alt="{t}Information{/t}"/>
<div style="z-index:250;width:100%;">
<div class="plugbottom">
{if $s_Trace != "" && $i_TraceCnt != 0}
......@@ -172,8 +172,8 @@ class msg_dialog
<img src="geticon.php?context=status&amp;icon=dialog-error&amp;size=32" alt="'._('Error').'"/>
<td style="width:100%">
<b>'.htmlentities($this->s_Title, ENT_COMPAT, 'UTF-8').'</b><br/>
'.htmlentities($this->s_Message, ENT_COMPAT, 'UTF-8').'<br><br/>
'._('Please fix the above error and reload the page.').'
