diff --git a/ag/include/clan_chat.inc.php b/ag/include/clan_chat.inc.php index 2169249..a48b5d9 100644 --- a/ag/include/clan_chat.inc.php +++ b/ag/include/clan_chat.inc.php @@ -52,6 +52,7 @@ function checkAccessRights($user_id, $clan_chat_id) { } function sendClanChatMessage($user_id, $clan_chat_id, $message) { + $message = addslashes($message); if(checkAccessRights($user_id, $clan_chat_id)) { $user = getUser($user_id); while(true) { @@ -88,7 +89,8 @@ function getClanChatMessages($requester, $clan_chat_id, $count, $asc, $msg_id = $qry = db_query($sql); while($row = mysql_fetch_assoc($qry)) { $result['max_id'] = max($result['max_id'], $row['msg_id']); - $result['chat_rows'][] = formatTimestampShortYear($row['zeit']) . ' ' . generateUserNameByID($row['user_id']) . ': ' . encodeNoHTMLWithBB($row['message']); + $message = stripslashes(encodeNoHTMLWithBB(stripslashes($row['message']))); + $result['chat_rows'][] = formatTimestampShortYear($row['zeit']) . ' ' . generateUserNameByID($row['user_id']) . ': ' . $message; } if(!$asc) {