From b3fa0c402e060622a5ed539a465d2fa98b1d2e13 Mon Sep 17 00:00:00 2001 From: Andrew Donnellan Date: Fri, 5 Jul 2019 13:27:41 +1000 Subject: filters: Escape State names when generating selector HTML States with names containing special characters are not correctly escaped when generating the select list. Use escape() to fix this. Signed-off-by: Andrew Donnellan --- patchwork/filters.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/patchwork/filters.py b/patchwork/filters.py index e2d2f59..fb644f9 100644 --- a/patchwork/filters.py +++ b/patchwork/filters.py @@ -262,7 +262,7 @@ class StateFilter(Filter): selected = ' selected="true"' out += '' % ( - state.id, selected, state.name) + state.id, selected, escape(state.name)) out += '' return mark_safe(out) -- cgit v1.2.3