fixed potential XSS vulnerability