summaryrefslogtreecommitdiff
path: root/lib
diff options
context:
space:
mode:
Diffstat (limited to 'lib')
-rw-r--r--lib/exe/spellcheck.php3
1 files changed, 2 insertions, 1 deletions
diff --git a/lib/exe/spellcheck.php b/lib/exe/spellcheck.php
index 65f80c5e8..aa1168136 100644
--- a/lib/exe/spellcheck.php
+++ b/lib/exe/spellcheck.php
@@ -272,7 +272,8 @@ function spell_resume(){
* Just send data back as received for UTF-8 testing
*/
function spell_utf8test(){
- print $_POST['data'];
+ // we need to return the raw value - substr protects against XSS
+ print substr($_POST['data'],0,3);
}
/**