</tr>
<tr>
<th align="right">Subject</th>
- <td><%= @message.title %></td>
+ <td><%= h(@message.title) %></td>
</tr>
<tr>
<th align="right">Date</th>
</tr>
<tr>
<th></th>
- <td><%= @message.body %></td>
+ <td><%= sanitize(@message.body) %></td>
</tr>
</table>
</tr>
<tr>
<th align="right">Subject</th>
- <td><%= @message.title %></td>
+ <td><%= h(@message.title) %></td>
</tr>
<tr>
<th align="right">Date</th>
</tr>
<tr>
<th></th>
- <td><%= @message.body %></td>
+ <td><%= sanitize(@message.body) %></td>
</tr>
</table>