diff --git a/message/user.php b/message/user.php index 4fd2839e22828..a20f85a6a375b 100644 --- a/message/user.php +++ b/message/user.php @@ -150,7 +150,7 @@ /// Then write it to our own screen immediately $time = userdate(time(), get_string('strftimemessage', 'chat')); - $message = '

'.$USER->firstname.' ['.$time.']: '.$message.'

'; + $message = '

'.addslashes($USER->firstname).' ['.$time.']: '.$message.'

'; $script = "