[Notifications] Escape HTML in destUrl and fileName
Ensures that a file or destination named <h1>foo.txt doesn't break the layout. It still goes through the normal HTML text filter, so remote file access isn't possible, merely screwing up the layout. (5.21 version of !628)
parent
b419a2b3
Please register or sign in to comment