From 3b3efa6b310e3d0022160161dda79f2217a84e4d Mon Sep 17 00:00:00 2001 From: Sam Date: Sun, 3 Jul 2022 18:16:20 +0100 Subject: [PATCH] Escape custom profile field value in user settings page --- modules/Core/pages/user/settings.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/Core/pages/user/settings.php b/modules/Core/pages/user/settings.php index f95fb7db7d..3d0097e709 100644 --- a/modules/Core/pages/user/settings.php +++ b/modules/Core/pages/user/settings.php @@ -512,7 +512,7 @@ $custom_fields_template[$field->name] = [ 'name' => Output::getClean($field->name), - 'value' => $field->value, + 'value' => Output::getClean($field->value), 'id' => $field->id, 'type' => $type, 'required' => $field->required,