diff --git a/src/Ui/media/Wrapper.coffee b/src/Ui/media/Wrapper.coffee index 584f1f0e..d2a7ac6a 100644 --- a/src/Ui/media/Wrapper.coffee +++ b/src/Ui/media/Wrapper.coffee @@ -531,7 +531,7 @@ class Wrapper if value instanceof Array value = @toHtmlSafe(value) else - value = String(value).replace(/&/g, '&').replace(//g, '>').replace(/"/g, '"') # Escape + value = String(value).replace(/&/g, '&').replace(//g, '>').replace(/"/g, '"').replace(/'/g, ''') # Escape dangerous characters value = value.replace(/<([\/]{0,1}(br|b|u|i|small))>/g, "<$1>") # Unescape b, i, u, br tags values[i] = value return values