small fix
[mir.git] / etc / open / editcomment.template
index dc73ede..7932a9d 100755 (executable)
@@ -179,7 +179,7 @@ ${lang("comment.formtitle")}
    </if>
 
 <form enctype="multipart/form-data" action="${actionURL}&do=opensession&sessiontype=comment" method="post">
-<input type="hidden" name="to_media" value="${to_media}">
+<input type="hidden" name="to_media" value="${utility.encodeHTML(to_media)}">
 
 <h2>
 ${lang("posting.step01")}