From 31d0bf81af079bc285ea439ac5160f9e45697c88 Mon Sep 17 00:00:00 2001 From: Simey Lameze Date: Thu, 24 Sep 2015 08:42:38 +0800 Subject: [PATCH] MDL-49940 mod_survey: Fix XSS on survey module --- mod/survey/lib.php | 2 +- mod/survey/report.php | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/mod/survey/lib.php b/mod/survey/lib.php index 934ed98c561..9d57fb36df0 100644 --- a/mod/survey/lib.php +++ b/mod/survey/lib.php @@ -189,7 +189,7 @@ function survey_user_complete($course, $user, $mod, $survey) { } else { $answertext = "No answer"; } - $table->data[] = array("$questiontext", $answertext); + $table->data[] = array("$questiontext", s($answertext)); } echo html_writer::table($table); diff --git a/mod/survey/report.php b/mod/survey/report.php index 1271ce9cd3b..66d366d6345 100644 --- a/mod/survey/report.php +++ b/mod/survey/report.php @@ -356,7 +356,7 @@ $OUTPUT->user_picture($a, array('courseid'=>$course->id)), "userid\">".fullname($a)."", userdate($a->time), - $answer1, $answer2); + s($answer1), s($answer2)); } } -- 2.11.4.GIT