diff --git a/xwiki-platform-core/xwiki-platform-flamingo/xwiki-platform-flamingo-skin/xwiki-platform-flamingo-skin-resources/src/main/resources/flamingo/delete.vm b/xwiki-platform-core/xwiki-platform-flamingo/xwiki-platform-flamingo-skin/xwiki-platform-flamingo-skin-resources/src/main/resources/flamingo/delete.vm index c1a64fa27218..643526ed1690 100644 --- a/xwiki-platform-core/xwiki-platform-flamingo/xwiki-platform-flamingo-skin/xwiki-platform-flamingo-skin-resources/src/main/resources/flamingo/delete.vm +++ b/xwiki-platform-core/xwiki-platform-flamingo/xwiki-platform-flamingo-skin/xwiki-platform-flamingo-skin-resources/src/main/resources/flamingo/delete.vm @@ -307,9 +307,9 @@ #if("$!{request.xredirect}" != '') - #set($cancelUrl = "$request.xredirect") + #getSanitizedURLAttributeValue('a','href',$request.xredirect,$doc.getURL(),$cancelUrl) #else - #set($cancelUrl = $doc.getURL()) + #set($cancelUrl = $escapetool.xml($doc.getURL())) #end $escapetool.xml($services.localization.render('cancel')) #end