diff --git a/cis/menu.php b/cis/menu.php index 089271e44..09859c413 100644 --- a/cis/menu.php +++ b/cis/menu.php @@ -103,12 +103,14 @@ ob_start(); if(isset($_GET['content_id']) && $_GET['content_id'] != '') { - $content_id = $_GET['content_id']; + // Uses urlencode to avoid XSS issues + $content_id = urlencode($_GET['content_id']); } else { $content_id = CIS_MENU_ENTRY_CONTENT; - } ?> + } + ?>