diff --git a/lib/documentmanagement/MDTree.inc b/lib/documentmanagement/MDTree.inc index 7477be9..0fbf66e 100644 --- a/lib/documentmanagement/MDTree.inc +++ b/lib/documentmanagement/MDTree.inc @@ -289,7 +289,7 @@ class MDTree { $extraclass = ' inactive'; } - $treeStr .= '
  • ' . $treeToRender->mapnodes[$subnode_val]->getName() . ''; + $treeStr .= '
  • ' . htmlentities($treeToRender->mapnodes[$subnode_val]->getName()) . ''; $treeStr .= $this->_evilTreeRecursion($subnode_val, $treeToRender, $inputname); $treeStr .= '
  • '; } @@ -301,7 +301,8 @@ class MDTree { if ($leaf === $this->activevalue) { $is_selected=' checked="checked"'; } - $treeStr .= '
  • ' . $treeToRender->lookups[$leaf]->getName() .''; + $sValue = htmlentities($treeToRender->lookups[$leaf]->getName()); + $treeStr .= '
  • ' . $sValue .''; $treeStr .= '
  • '; } } }