Index: trunk/extensions/DonationInterface/gateway_forms/RapidHtml.php |
— | — | @@ -91,7 +91,8 @@ |
92 | 92 | // Get error passed via query string |
93 | 93 | $error = $wgRequest->getText( 'error' ); |
94 | 94 | if ( $error ) { |
95 | | - $form_errors['general'][] = $error; |
| 95 | + // We escape HTML here since only quotes are escaped later |
| 96 | + $form_errors['general'][] = htmlspecialchars( $error ); |
96 | 97 | } |
97 | 98 | |
98 | 99 | if ( $country != '' ){ |