Escape generated password in mobileconfig

Escape ampersand, less than, greater than to avoid generating invalid XML.

Fixes #7171
This commit is contained in:
Michael Kuron
2026-05-02 16:24:01 +02:00
committed by Michael Kuron
parent 886dbcc419
commit ffbc37a00c

View File

@@ -65,6 +65,7 @@ if (isset($_GET['app_password'])) {
$attr['protocols'][] = 'dav_access';
}
app_passwd("add", $attr);
$password = htmlspecialchars($password, ENT_NOQUOTES);
} else {
$app_password = false;
}