From 9c580277efbafe68e31d675e0b2f71e100665783 Mon Sep 17 00:00:00 2001 From: Tom Hughes Date: Mon, 7 Jul 2008 08:06:56 +0000 Subject: [PATCH] Sanitize user descriptions properly. --- app/views/user/view.rhtml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/views/user/view.rhtml b/app/views/user/view.rhtml index f27ce6f0a..c5fc6388d 100644 --- a/app/views/user/view.rhtml +++ b/app/views/user/view.rhtml @@ -33,7 +33,7 @@ <% end %>

Description

-
<%= simple_format(@this_user.description) %>
+
<%= htmlize(@this_user.description) %>
<% if @this_user.home_lat.nil? or @this_user.home_lon.nil? %>

User location

-- 2.43.2