diff --git a/addons/mail/static/src/js/composer.js b/addons/mail/static/src/js/composer.js index 4112a8498cf..2965ccf9298 100644 --- a/addons/mail/static/src/js/composer.js +++ b/addons/mail/static/src/js/composer.js @@ -398,7 +398,7 @@ var Composer = Widget.extend({ preprocess_message: function () { // Return a deferred as this function is extended with asynchronous // behavior for the chatter composer - var value = this.$input.val().replace(/\n|\r/g, '
'); + var value = _.escape(this.$input.val()).replace(/\n|\r/g, '
'); return $.when({ content: this.mention_manager.generate_links(value), attachment_ids: _.pluck(this.get('attachment_ids'), 'id'), diff --git a/addons/mail/static/src/js/window_manager.js b/addons/mail/static/src/js/window_manager.js index fe60dff4bd5..f217d929c20 100644 --- a/addons/mail/static/src/js/window_manager.js +++ b/addons/mail/static/src/js/window_manager.js @@ -38,6 +38,7 @@ function open_chat (session) { }); chat_session.window.on("post_message", null, function (message, channel_id) { + message.content = _.escape(message.content); chat_manager.post_message(message, {channel_id: channel_id}); }); chat_session.window.on("messages_read", null, function () {