diff options
-rw-r--r-- | include/functions_comment.inc.php | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/include/functions_comment.inc.php b/include/functions_comment.inc.php index dc218a2ff..b0d704798 100644 --- a/include/functions_comment.inc.php +++ b/include/functions_comment.inc.php @@ -135,6 +135,7 @@ SELECT COUNT(*) AS user_exists // website if (!empty($comm['website_url'])) { + $comm['website_url'] = strip_tags($comm['website_url']); if (!preg_match('/^https?/i', $comm['website_url'])) { $comm['website_url'] = 'http://'.$comm['website_url']; @@ -338,6 +339,7 @@ function update_user_comment($comment, $post_key) // website if (!empty($comment['website_url'])) { + $comm['website_url'] = strip_tags($comm['website_url']); if (!preg_match('/^https?/i', $comment['website_url'])) { $comment['website_url'] = 'http://'.$comment['website_url']; |