diff --git a/main/survey/fillsurvey.php b/main/survey/fillsurvey.php index fa1406efd3..da6dd45314 100755 --- a/main/survey/fillsurvey.php +++ b/main/survey/fillsurvey.php @@ -1254,7 +1254,9 @@ if (isset($questions) && is_array($questions)) { $display = new $ch_type(); // @todo move this in a function. $form->addHtml('
'); - $form->addHtml('
'.$questionNumber.'. '.strip_tags($question['survey_question']).'
'); + $form->addHtml('
'.$questionNumber.'.
'); + $form->addHtml('
'.Security::remove_XSS($question['survey_question']).'
'); + $userAnswerData = SurveyUtil::get_answers_of_question_by_user($question['survey_id'], $question['question_id']); $finalAnswer = null; diff --git a/main/survey/preview.php b/main/survey/preview.php index b3825f04cc..e791c9c245 100755 --- a/main/survey/preview.php +++ b/main/survey/preview.php @@ -237,7 +237,8 @@ if (api_is_course_admin() || /** @var survey_question $display */ $display = new $ch_type(); $form->addHtml('
'); - $form->addHtml('
'.$counter.'. '.strip_tags($question['survey_question']).'
'); + $form->addHtml('
'.$counter.'.
'); + $form->addHtml('
'.Security::remove_XSS($question['survey_question']).'
'); $display->render($form, $question); $form->addHtml('
'); $counter++;