fix view message xss

This commit is contained in:
xiaomlove
2023-11-22 14:50:14 +08:00
committed by GitHub
parent b2a2470cee
commit 8fc88d3ada

View File

@@ -229,7 +229,7 @@ $reply = " [ <a href=\"sendmessage.php?receiver=" . $message['sender'] . "&reply
}
}
$body = format_comment($message['msg']);
$body = htmlspecialchars_decode($body);
//$body = htmlspecialchars_decode($body);
$added = $message['added'];
if ($message['sender'] == $CURUSER['id'])
{