From 05fb4cbca4f93ea55d55da3b2e3a7f2f5a174b21 Mon Sep 17 00:00:00 2001 From: czaks Date: Wed, 31 Jul 2013 20:33:27 -0400 Subject: [PATCH] markup modifiers: there was a plan for adding markup to ban reasons, but assignment was missing; escape markup there too --- inc/mod/ban.php | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/inc/mod/ban.php b/inc/mod/ban.php index 9166223f..45973ae6 100644 --- a/inc/mod/ban.php +++ b/inc/mod/ban.php @@ -61,7 +61,8 @@ function ban($mask, $reason, $length, $board) { $query->bindValue(':mod', $mod['id']); $query->bindValue(':time', time()); if ($reason !== '') { - markup($reason); + $reason = escape_markup_modifiers($reason); + $reason = markup($reason); $query->bindValue(':reason', $reason); } else $query->bindValue(':reason', null, PDO::PARAM_NULL);