diff --git a/core/groups/group_permissions.php b/core/groups/group_permissions.php index 077b09a611..0ee2216dbf 100644 --- a/core/groups/group_permissions.php +++ b/core/groups/group_permissions.php @@ -328,7 +328,7 @@ echo " if (new_group_name != null) {\n"; echo " new_group_desc = prompt('".$text['message-new_group_description']."');\n"; echo " if (new_group_desc != null) {\n"; - echo " window.location = 'permissions_copy.php?group_name=".$group_name."&new_group_name=' + new_group_name + '&new_group_desc=' + new_group_desc;\n"; + echo " window.location = 'permissions_copy.php?group_name=".escape($group_name)."&new_group_name=' + new_group_name + '&new_group_desc=' + new_group_desc;\n"; echo " }\n"; echo " }\n"; echo " }\n"; @@ -352,11 +352,11 @@ //show the content echo "