Index: typo3/sysext/cms/tslib/class.tslib_content.php =================================================================== --- typo3/sysext/cms/tslib/class.tslib_content.php (Revision 9766) +++ typo3/sysext/cms/tslib/class.tslib_content.php (Arbeitskopie) @@ -1809,7 +1809,7 @@ } if ($val && strcspn($val,'#/')) { // label: - $confData['label'] = trim($parts[0]); + $confData['label'] = t3lib_div::removeXSS(trim($parts[0])); // field: $fParts = explode(',',$parts[1]); $fParts[0]=trim($fParts[0]); @@ -1835,6 +1835,7 @@ } else { $confData['fieldname'] = str_replace(' ','_',trim($typeParts[0])); } + $confData['fieldname'] = htmlspecialchars($confData['fieldname']); $fieldCode=''; if ($conf['wrapFieldName']) {