diff --git a/CHANGELOG b/CHANGELOG index b85655b..800977c 100644 --- a/CHANGELOG +++ b/CHANGELOG @@ -1,5 +1,6 @@ Add logout button to session view and allow unbanning kicked sessions Allow changing message sort direction +Don't escape CSS (fixes use of html entities) Version 1.21 - Aug. 29, 2016 Don't display empty option for system messages in delete messages by name diff --git a/chat.php b/chat.php index 28c1abe..a186d4c 100644 --- a/chat.php +++ b/chat.php @@ -3181,7 +3181,6 @@ function save_setup($C){ $_REQUEST['rulestxt']=preg_replace("/(\r?\n|\r\n?)/", '
', $_REQUEST['rulestxt']); $_REQUEST['chatname']=htmlspecialchars($_REQUEST['chatname']); $_REQUEST['redirect']=htmlspecialchars($_REQUEST['redirect']); - $_REQUEST['css']=htmlspecialchars($_REQUEST['css']); if(!preg_match('/^[a-f0-9]{6}$/i', $_REQUEST['colbg'])){ unset($_REQUEST['colbg']); }