diff --git a/core/js/share.js b/core/js/share.js
index 145c31a86c..34f24da4df 100644
--- a/core/js/share.js
+++ b/core/js/share.js
@@ -309,12 +309,12 @@ OC.Share={
if (permissions & OC.PERMISSION_SHARE) {
shareChecked = 'checked="checked"';
}
- var html = '
';
+ var html = '';
html += '';
if(shareWith.length > 14){
- html += shareWithDisplayName.substr(0,11) + '...';
+ html += escapeHTML(shareWithDisplayName.substr(0,11) + '...');
}else{
- html += shareWithDisplayName;
+ html += escapeHTML(shareWithDisplayName);
}
if (possiblePermissions & OC.PERMISSION_CREATE || possiblePermissions & OC.PERMISSION_UPDATE || possiblePermissions & OC.PERMISSION_DELETE) {
if (editChecked == '') {