escaping fix from Emanuele Aina
[ikiwiki.git] / IkiWiki / CGI.pm
index 6e1efbd69927f1199b0af6ccee45285d8ef7ea81..be06db49c8d14294a3c2881c1b97f5771ba8aa7f 100644 (file)
@@ -81,7 +81,7 @@ sub cgi_recentchanges ($) { #{{{
        my $changelog=[rcs_recentchanges(100)];
        foreach my $change (@$changelog) {
                $change->{when} = concise(ago($change->{when}));
-               $change->{user} = htmllink("", "", $change->{user}, 1);
+               $change->{user} = htmllink("", "", escapeHTML($change->{user}), 1);
                $change->{pages} = [
                        map {
                                $_->{link} = htmllink("", "", $_->{page}, 1);