Affected Issues  0022568: CVE-2017-7241: XSS in move_attachments_page.php

Fix XSS in move_attachments_page.php

Yelin and Zhangdongsheng from VenusTech
reported a vulnerability in the Move Attachments admin page, allowing
an attacker to inject arbitrary code through a crafted 'type'

Sanitize the 'type' parameter prior to output, to ensure HTML special
characters are properly escaped.

Fixes 0022568

