Properly escape title in rssFeed.tpl
authorTim Düsterhus <timwolla@googlemail.com>
Sat, 1 Mar 2014 20:56:13 +0000 (21:56 +0100)
committerTim Düsterhus <timwolla@googlemail.com>
Sat, 1 Mar 2014 20:56:13 +0000 (21:56 +0100)
com.woltlab.wcf/templates/rssFeed.tpl

index 86994a87f55d387496aa2dfb224f74bc299eaeb4..04dc55a78aa70905d8d732821fca477d7c7d7744 100644 (file)
@@ -6,7 +6,7 @@
        xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
 >
        <channel>
-               <title><![CDATA[{if $title}{@$title} - {/if}{@PAGE_TITLE|language|escapeCDATA}]]></title>
+               <title><![CDATA[{if $title}{@$title|escapeCDATA} - {/if}{@PAGE_TITLE|language|escapeCDATA}]]></title>
                <link><![CDATA[{@$baseHref|escapeCDATA}]]></link>
                <description><![CDATA[{@PAGE_DESCRIPTION|escapeCDATA}]]></description>
                <language>{@$__wcf->language->getFixedLanguageCode()}</language>