diff --git a/file/lib/form/ChatForm.class.php b/file/lib/form/ChatForm.class.php
index 4a8ec7e..9699c8f 100644
--- a/file/lib/form/ChatForm.class.php
+++ b/file/lib/form/ChatForm.class.php
@@ -45,7 +45,7 @@ public function readData() {
public function readFormParameters() {
parent::readFormParameters();
- if (isset($_REQUEST['text'])) $this->message = StringUtil::trim($_REQUEST['text']);
+ if (isset($_REQUEST['text'])) $this->message = \wcf\util\MessageUtil::stripCrap(StringUtil::trim($_REQUEST['text']));
if (isset($_REQUEST['smilies'])) $this->enableSmilies = intval($_REQUEST['smilies']);
}
diff --git a/package.xml b/package.xml
index df7cda5..8609d5e 100644
--- a/package.xml
+++ b/package.xml
@@ -19,6 +19,7 @@
com.woltlab.wcf
com.woltlab.wcf.bbcode
com.woltlab.wcf.acl
+ com.woltlab.wcf.message