Commit dedb2405 authored by Richard Mansfield's avatar Richard Mansfield
Browse files

HTML Escape friend request message

parent 59e8878c
......@@ -35,7 +35,7 @@
</div>
{if $relationship == 'pending'}
<div class="message">
{str tag='whymakemeyourfriend' section='group'} {$message}
{str tag='whymakemeyourfriend' section='group'} {$message|escape}
{$requestform}
</div>
{/if}
......
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment