diff --git a/administrator/components/com_users/views/users/tmpl/modal.php b/administrator/components/com_users/views/users/tmpl/modal.php
index e63a8d653e177..6550f92934148 100644
--- a/administrator/components/com_users/views/users/tmpl/modal.php
+++ b/administrator/components/com_users/views/users/tmpl/modal.php
@@ -75,7 +75,7 @@
+ data-user-field="escape($field);?>" onclick="if (window.parent) window.parent.jSelectUser(this);">
name; ?>
|
diff --git a/layouts/joomla/form/field/user.php b/layouts/joomla/form/field/user.php
index 0905e6651b2de..01b4d399d6f30 100644
--- a/layouts/joomla/form/field/user.php
+++ b/layouts/joomla/form/field/user.php
@@ -47,7 +47,7 @@
*/
$link = 'index.php?option=com_users&view=users&layout=modal&tmpl=component&required='
- . ($required ? 1 : 0) . '&field={field-user-id}'
+ . ($required ? 1 : 0) . '&field=' . htmlspecialchars($id, ENT_COMPAT, 'UTF-8')
. (isset($groups) ? ('&groups=' . base64_encode(json_encode($groups))) : '')
. (isset($excluded) ? ('&excluded=' . base64_encode(json_encode($excluded))) : '');