Skip to content

Commit f27b8d1

Browse files
authored
Merge pull request #1327 from nowackipawel/patch-11
FIX form_hidden and form_open - value escaping as is in form_input.
2 parents 9ab2a11 + 846e098 commit f27b8d1

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

system/Helpers/form_helper.php

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -92,7 +92,7 @@ function form_open(string $action = '', $attributes = [], array $hidden = []): s
9292
{
9393
foreach ($hidden as $name => $value)
9494
{
95-
$form .= '<input type="hidden" name="' . $name . '" value="' . $value . '" style="display: none;" />' . "\n";
95+
$form .= '<input type="hidden" name="' . $name . '" value="' . esc($value,'html') . '" style="display: none;" />' . "\n";
9696
}
9797
}
9898

@@ -171,7 +171,7 @@ function form_hidden($name, $value = '', bool $recursing = false): string
171171

172172
if ( ! is_array($value))
173173
{
174-
$form .= '<input type="hidden" name="' . $name . '" value="' . $value . "\" />\n";
174+
$form .= '<input type="hidden" name="' . $name . '" value="' . esc($value,'html') . "\" />\n";
175175
}
176176
else
177177
{

0 commit comments

Comments
 (0)