diff --git a/main/calendar/agenda.inc.php b/main/calendar/agenda.inc.php index 84749dd505..25d1f3da7f 100755 --- a/main/calendar/agenda.inc.php +++ b/main/calendar/agenda.inc.php @@ -478,7 +478,7 @@ function display_monthcalendar($month, $year, $agenda_items) { $start_time = api_convert_and_format_date($value['start_date'], TIME_NO_SEC_FORMAT); $end_time = ''; if (!empty($value['end_date']) && $value['end_date'] != '0000-00-00 00:00:00') { - $end_time = '- '.api_convert_and_format_date($value['end_date'],DATE_TIME_FORMAT_LONG); + $end_time = '- '.api_convert_and_format_date($value['end_date'],DATE_TIME_FORMAT_LONG).''; } $complete_time = ''.api_convert_and_format_date($value['start_date'], DATE_TIME_FORMAT_LONG).' '.$end_time; $time = ''.$start_time.''; diff --git a/main/calendar/myagenda.inc.php b/main/calendar/myagenda.inc.php index 87ef08f95a..60b64e8938 100755 --- a/main/calendar/myagenda.inc.php +++ b/main/calendar/myagenda.inc.php @@ -212,10 +212,11 @@ function display_mymonthcalendar($agendaitems, $month, $year, $weekdaynames=arra $items = $agendaitems[$curday]; foreach($items as $value) { + $value['title'] = Security::remove_XSS($value['title']); $start_time = api_convert_and_format_date($value['start_date'], TIME_NO_SEC_FORMAT); $end_time = ''; if (!empty($value['end_date']) && $value['end_date'] != '0000-00-00 00:00:00') { - $end_time = '- '.api_convert_and_format_date($value['end_date'], DATE_TIME_FORMAT_LONG); + $end_time = '- '.api_convert_and_format_date($value['end_date'], DATE_TIME_FORMAT_LONG).''; } $complete_time = ''.api_convert_and_format_date($value['start_date'], DATE_TIME_FORMAT_LONG).' '.$end_time; $time = ''.$start_time.''; @@ -244,14 +245,13 @@ function display_mymonthcalendar($agendaitems, $month, $year, $weekdaynames=arra $url = Display::url($value['title'], '#', array('id'=>$value['calendar_type'].'_'.$value['id'],'class'=>'opener')); $result .= $time.' '.$icon.' '.Display::div($url); - //Hidden content - $content = Display::div($icon.Display::tag('h2', $value['title']).$complete_time.$value['content']); - //Main div - $result .= Display::div($content, array('id'=>'main_'.$value['calendar_type'].'_'.$value['id'], 'class' => 'dialog', 'style' => 'display:none')); - - $result .= ''; + $result .= ''; echo $result; + + //Hidden content + $content = Display::div($icon.Display::tag('h2', $value['title']).$complete_time.Security::remove_XSS($value['content'])); + echo Display::div($content, array('id'=>'main_'.$value['calendar_type'].'_'.$value['id'], 'class' => 'dialog')); } } echo "";