SpecialActiveUsers: escape group names
authorNiklas Laxström <niklas.laxstrom@gmail.com>
Wed, 30 Nov 2016 13:53:11 +0000 (14:53 +0100)
committerNiklas Laxström <niklas.laxstrom@gmail.com>
Wed, 30 Nov 2016 13:53:11 +0000 (14:53 +0100)
Change-Id: I1a4d1501b8481d9f670916818fe7f75e983c2800

includes/specials/SpecialActiveusers.php

index 7e29be0..a01e9b2 100644 (file)
@@ -86,7 +86,7 @@ class SpecialActiveUsers extends SpecialPage {
                $groups = User::getAllGroups();
 
                foreach ( $groups as $group ) {
-                       $msg = User::getGroupName( $group );
+                       $msg = htmlspecialchars( User::getGroupName( $group ) );
                        $options[$msg] = $group;
                }