forked from mirrors/easyappointments
Escape the user display name in the backend section
This commit is contained in:
parent
2255c84778
commit
bddc5cbeb7
1 changed files with 1 additions and 1 deletions
|
@ -86,7 +86,7 @@
|
||||||
<a class="nav-link dropdown-toggle" href="#" data-bs-toggle="dropdown"
|
<a class="nav-link dropdown-toggle" href="#" data-bs-toggle="dropdown"
|
||||||
data-tippy-content="<?= lang('settings_hint') ?>">
|
data-tippy-content="<?= lang('settings_hint') ?>">
|
||||||
<i class="fas fa-user me-2"></i>
|
<i class="fas fa-user me-2"></i>
|
||||||
<?= vars('user_display_name') ?>
|
<?= e(vars('user_display_name')) ?>
|
||||||
</a>
|
</a>
|
||||||
<div class="dropdown-menu dropdown-menu-end">
|
<div class="dropdown-menu dropdown-menu-end">
|
||||||
<?php if (can('view', PRIV_SYSTEM_SETTINGS)): ?>
|
<?php if (can('view', PRIV_SYSTEM_SETTINGS)): ?>
|
||||||
|
|
Loading…
Reference in a new issue