From 90881f2fa9a7ee022a4d1416e45aaa140bc1ab3c Mon Sep 17 00:00:00 2001 From: Laurent Destailleur Date: Mon, 7 Nov 2016 00:09:53 +0100 Subject: [PATCH] FIX Sanitize title of ajax_dialog --- htdocs/core/lib/ajax.lib.php | 3 ++- htdocs/main.inc.php | 2 +- 2 files changed, 3 insertions(+), 2 deletions(-) diff --git a/htdocs/core/lib/ajax.lib.php b/htdocs/core/lib/ajax.lib.php index 4b0ae91ee3f..3914b59b9f6 100644 --- a/htdocs/core/lib/ajax.lib.php +++ b/htdocs/core/lib/ajax.lib.php @@ -322,7 +322,8 @@ function ajax_dialog($title,$message,$w=350,$h=150) { global $langs; - $msg= '
'; + $newtitle=dol_textishtml($title)?dol_string_nohtmltag($title,1):$title; + $msg= '
'; $msg.= $message; $msg.= '
'."\n"; $msg.= '