diff --git a/phpmyfaq/admin/instances.php b/phpmyfaq/admin/instances.php index a4fd8b3fae..a2374dfa57 100644 --- a/phpmyfaq/admin/instances.php +++ b/phpmyfaq/admin/instances.php @@ -243,6 +243,10 @@ class="btn btn-danger pmf-instance-delete" const admin = $('#admin').val(); const password = $('#password').val(); + const escape = (unsafe) => { + return unsafe.replaceAll('&', '&').replaceAll('<', '<').replaceAll('>', '>').replaceAll('"', '"').replaceAll("'", '''); + } + $.ajax({ url: 'index.php', type: 'GET', @@ -256,8 +260,8 @@ class="btn btn-danger pmf-instance-delete" '' + '' + data.added + '' + '' + data.url + '' + - '' + instance + '' + - '' + comment + '' + + '' + escape(instance) + '' + + '' + escape(comment) + '' + '' + '' +