Browse Source

call escape markup on results

Igor Vaynberg 12 years ago
parent
commit
e78dc69a6b
1 changed files with 1 additions and 1 deletions
  1. 1 1
      select2.js

+ 1 - 1
select2.js

@@ -698,7 +698,7 @@ the specific language governing permissions and limitations under the Apache Lic
                             label=$(document.createElement("div"));
                             label.addClass("select2-result-label");
 
-                            formatted=opts.formatResult(result, label, query);
+                            formatted=opts.escapeMarkup(opts.formatResult(result, label, query));
                             if (formatted!==undefined) {
                                 label.html(formatted);
                             }