diff options
author | Morris Jobke <hey@morrisjobke.de> | 2019-03-26 17:45:26 +0300 |
---|---|---|
committer | Morris Jobke <hey@morrisjobke.de> | 2019-03-26 17:45:51 +0300 |
commit | 7ac1419fc22a2200084fbf3c4ba1141c8f6f97b5 (patch) | |
tree | 1ad61d6346dc9ad59df305faa4c61e39c53ca852 | |
parent | ea799cdb546e65816a70f92ead6c0c8b8166c9ef (diff) |
Quote updater URLv14.0.9RC1
Signed-off-by: Morris Jobke <hey@morrisjobke.de>
-rw-r--r-- | index.php | 2 |
1 files changed, 1 insertions, 1 deletions
@@ -1737,7 +1737,7 @@ if(strpos($updaterUrl, 'index.php') === false) { <li id="step-done" class="step <?php if($stepNumber >= 12) { echo 'passed-step'; }?>"> <h2>Done</h2> <div class="output hidden"> - <a class="button" href="<?php echo str_replace('/index.php', '/../', $updaterUrl); ?>">Go back to your Nextcloud instance to finish the update</a> + <a class="button" href="<?php echo htmlspecialchars(str_replace('/index.php', '/../', $updaterUrl), ENT_QUOTES); ?>">Go back to your Nextcloud instance to finish the update</a> </div> </li> </ul> |