diff --git a/message/user.php b/message/user.php index 4fd2839e22828..a20f85a6a375b 100644 --- a/message/user.php +++ b/message/user.php @@ -150,7 +150,7 @@ /// Then write it to our own screen immediately $time = userdate(time(), get_string('strftimemessage', 'chat')); - $message = '
'.$USER->firstname.' ['.$time.']: '.$message.'
'; + $message = ''.addslashes($USER->firstname).' ['.$time.']: '.$message.'
'; $script = "