diff --git a/core/groups/groupedit.php b/core/groups/groupedit.php index 1ef25ba4e8..48bd71ffb3 100644 --- a/core/groups/groupedit.php +++ b/core/groups/groupedit.php @@ -228,7 +228,7 @@ echo " if (new_group_name != null) {\n"; echo " new_group_desc = prompt('".$text['message-new_group_description']."');\n"; echo " if (new_group_desc != null) {\n"; - echo " window.location = 'permissions_copy.php?group_name=".$group_name."&new_group_name=' + new_group_name + '&new_group_desc=' + new_group_desc;\n"; + echo " window.location = 'permissions_copy.php?group_name=".escape($group_name)."&new_group_name=' + new_group_name + '&new_group_desc=' + new_group_desc;\n"; echo " }\n"; echo " }\n"; echo " }\n"; @@ -236,7 +236,7 @@ //show the content echo "