diff --git a/webui/src/main/java/com/muwire/webui/DownloadServlet.java b/webui/src/main/java/com/muwire/webui/DownloadServlet.java index 9b93c79a..cd0484fa 100644 --- a/webui/src/main/java/com/muwire/webui/DownloadServlet.java +++ b/webui/src/main/java/com/muwire/webui/DownloadServlet.java @@ -213,7 +213,7 @@ public class DownloadServlet extends HttpServlet { void toXML(StringBuilder sb) { sb.append(""); sb.append("").append(Base64.encode(infoHash.getRoot())).append(""); - sb.append("").append(name).append(""); + sb.append("").append(Util.escapeHTMLinXML(name)).append(""); sb.append("").append(state.toString()).append(""); sb.append("").append(DataHelper.formatSize2Decimal(speed, false)).append("B/sec").append(""); String ETAString;