escape course titles names

pull/4090/head
Juan Cortizas Ponte 4 years ago
parent 04a13cec2f
commit ae7952743d
  1. 4
      main/admin/access_url_edit_courses_to_url.php

@ -197,7 +197,7 @@ $url_list = UrlManager::get_url_data();
<?php
foreach ($no_course_list as $no_course) {
?>
<option value="<?php echo $no_course['id']; ?>" title="<?php echo $no_course['title'].' ('.$no_course['code'].')'; ?>"><?php echo $no_course['title'].' ('.$no_course['code'].')'; ?></option>
<option value="<?php echo $no_course['id']; ?>" title="<?php echo htmlentities($no_course['title'], ENT_QUOTES).' ('.$no_course['code'].')'; ?>"><?php echo $no_course['title'].' ('.$no_course['code'].')'; ?></option>
<?php
}
unset($no_course_list); ?>
@ -234,7 +234,7 @@ $url_list = UrlManager::get_url_data();
<?php
foreach ($course_list as $course) {
$courseInfo = api_get_course_info_by_id($course['id']); ?>
<option value="<?php echo $course['id']; ?>" title="<?php echo $course['title'].' ('.$courseInfo['code'].')'; ?>">
<option value="<?php echo $course['id']; ?>" title="<?php echo htmlentities($course['title'], ENT_QUOTES).' ('.$courseInfo['code'].')'; ?>">
<?php echo $course['title'].' ('.$courseInfo['code'].')'; ?>
</option>
<?php

Loading…
Cancel
Save