diff --git a/security/ChangePasswordForm.php b/security/ChangePasswordForm.php index f4ae9fc06..5a1f9d868 100644 --- a/security/ChangePasswordForm.php +++ b/security/ChangePasswordForm.php @@ -129,7 +129,7 @@ class ChangePasswordForm extends Form { _t( 'Member.INVALIDNEWPASSWORD', "We couldn't accept that password: {password}", - array('password' => nl2br("\n".$isValid->starredList())) + array('password' => nl2br("\n".Convert::raw2xml($isValid->starredList()))) ), "bad", false