diff --git a/chat.php b/chat.php index 0ed230c..7b4f291 100644 --- a/chat.php +++ b/chat.php @@ -2228,14 +2228,14 @@ function send_del_confirm(): void echo hidden('multi', 'on'); } if(isset($_POST['sendto'])){ - echo hidden('sendto', $_POST['sendto']); + echo hidden('sendto', htmlspecialchars($_POST['sendto'])); } - echo hidden('confirm', 'yes').hidden('what', $_POST['what']).submit(_('Yes'), 'class="delbutton"').'