aboutsummaryrefslogtreecommitdiffstats
path: root/template/standard/html/feed/item_page.php
diff options
context:
space:
mode:
authorThomas Lange <code@nerdmind.de>2017-04-24 17:15:41 +0200
committerThomas Lange <code@nerdmind.de>2017-04-24 17:15:41 +0200
commit39944454324b4c66b8cf2444cca17c149208dfac (patch)
tree69a3296ef2a7edee6a65dcce52d50530a6f51aac /template/standard/html/feed/item_page.php
parent1269b210f28591b3fda52ecc41b9d7bf1e598555 (diff)
downloadblog-39944454324b4c66b8cf2444cca17c149208dfac.tar.gz
blog-39944454324b4c66b8cf2444cca17c149208dfac.tar.xz
blog-39944454324b4c66b8cf2444cca17c149208dfac.zip
HTML escaping is required to prevent XML validation errors for some characters like "&".
Diffstat (limited to 'template/standard/html/feed/item_page.php')
-rw-r--r--template/standard/html/feed/item_page.php2
1 files changed, 1 insertions, 1 deletions
diff --git a/template/standard/html/feed/item_page.php b/template/standard/html/feed/item_page.php
index ac3d197..f1a7a4d 100644
--- a/template/standard/html/feed/item_page.php
+++ b/template/standard/html/feed/item_page.php
@@ -13,7 +13,7 @@
<guid isPermaLink="false"><?=$PAGE['GUID']?></guid>
<pubDate><?=parseDatetime($PAGE['ATTR']['TIME_INSERT'], '[RFC2822]')?></pubDate>
<dc:creator><?=escapeHTML($USER['ATTR']['FULLNAME'])?></dc:creator>
- <description><?=description($PAGE['BODY']['HTML'], 400)?></description>
+ <description><?=escapeHTML(description($PAGE['BODY']['HTML'], 400))?></description>
<content:encoded>
<![CDATA[
<?=$PAGE['BODY']['HTML']?>