Escape characters that were unescaped by the parser
authorGuy Van den Broeck <guyvdb@users.mediawiki.org>
Wed, 20 Aug 2008 19:19:36 +0000 (19:19 +0000)
committerGuy Van den Broeck <guyvdb@users.mediawiki.org>
Wed, 20 Aug 2008 19:19:36 +0000 (19:19 +0000)
includes/HTMLDiff.php

index 8318deb..614b86d 100644 (file)
@@ -1714,6 +1714,6 @@ class DelegatingContentHandler {
        }
 
        function characters($chars){
-               $this->delegate->addHtml($chars);
+               $this->delegate->addHtml(htmlspecialchars($chars));
        }
 }