- <input type="hidden" name="input_subject" value="<TMPL_VAR input_subject ESCAPE=HTML>">
- <input type="hidden" name="input_body" value="<TMPL_VAR input_body ESCAPE=HTML>">
- <input type="hidden" name="input_attachment" value="<TMPL_VAR input_attachment ESCAPE=HTML>">
+ <input type="hidden" name="input_subject" value="[% HTML.escape(input_subject) %]">
+ <input type="hidden" name="input_body" value="[% HTML.escape(input_body) %]">
+ <input type="hidden" name="input_attachment" value="[% HTML.escape(input_attachment) %]">