From fabed34a993b8ee00aab8991555113debdcf1d4a Mon Sep 17 00:00:00 2001 From: Laurent Destailleur Date: Mon, 23 Nov 2020 21:47:51 +0100 Subject: [PATCH] FIX #15481 --- htdocs/user/passwordforgotten.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/htdocs/user/passwordforgotten.php b/htdocs/user/passwordforgotten.php index 789d67544a3..b29bb0e6d70 100644 --- a/htdocs/user/passwordforgotten.php +++ b/htdocs/user/passwordforgotten.php @@ -71,7 +71,7 @@ if ($action == 'validatenewpassword' && $username && $passwordhash) $result = $edituser->fetch('', $_GET["username"]); if ($result < 0) { - $message = '
'.$langs->trans("ErrorLoginDoesNotExists", $username).'
'; + $message = '
'.dol_escape_htmltag($langs->trans("ErrorLoginDoesNotExists", $username)).'
'; } else { if (dol_verifyHash($edituser->pass_temp, $passwordhash)) {