From 7daa19ff2ea4af2978ad7ea43b6545e8d1aa1e5c Mon Sep 17 00:00:00 2001 From: Dominik Csapak Date: Fri, 19 Oct 2018 12:36:45 +0200 Subject: [PATCH] dc/user: render user fullnames htmlEncoded Signed-off-by: Dominik Csapak Signed-off-by: Thomas Lamprecht --- www/manager6/dc/UserView.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/www/manager6/dc/UserView.js b/www/manager6/dc/UserView.js index 6dfc1041..5f8bed17 100644 --- a/www/manager6/dc/UserView.js +++ b/www/manager6/dc/UserView.js @@ -96,7 +96,7 @@ Ext.define('PVE.dc.UserView', { var first = firstname || ''; var last = record.data.lastname || ''; - return first + " " + last; + return Ext.htmlEncode(first + " " + last); }; var render_username = function(userid) {