forked from Wavyzz/dolibarr
Fix: escape html tag value
This commit is contained in:
@@ -1105,7 +1105,7 @@ function form_constantes($tableau)
|
|||||||
}
|
}
|
||||||
else
|
else
|
||||||
{
|
{
|
||||||
print '<input type="text" class="flat" size="48" name="constvalue" value="'.$obj->value.'">';
|
print '<input type="text" class="flat" size="48" name="constvalue" value="'.dol_escape_htmltag($obj->value).'">';
|
||||||
print '</td><td>';
|
print '</td><td>';
|
||||||
print '<input type="hidden" name="consttype" value="chaine">';
|
print '<input type="hidden" name="consttype" value="chaine">';
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user