diff --git a/include/utils/VtlibUtils.php b/include/utils/VtlibUtils.php index 762cf4e536889a02547862293cb07ad8dd4ae129..23bab2d187f66dfec20c1a922a5108a1b100632e 100644 --- a/include/utils/VtlibUtils.php +++ b/include/utils/VtlibUtils.php @@ -882,10 +882,10 @@ function jsEscape($str) { switch ($chr) { case "'": case '"': - case "\n"; - case "\r"; - case "&"; - case "\\"; + case "\n": + case "\r": + case "&": + case "\\": case "<": case ">": $output .= sprintf("\\u%04x", $chrNum);