From 5ba1ef5df7df30a61c837f31572477d0b8b0eb38 Mon Sep 17 00:00:00 2001 From: Jean-Philippe Lang Date: Sat, 30 Jul 2011 11:21:19 +0000 Subject: [PATCH] HTML escape. git-svn-id: svn+ssh://rubyforge.org/var/svn/redmine/trunk@6329 e93f8b46-1217-0410-a6f0-8f06a7374b81 --- app/views/projects/show.rhtml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/app/views/projects/show.rhtml b/app/views/projects/show.rhtml index 7cc554c84..0c35c1fa5 100644 --- a/app/views/projects/show.rhtml +++ b/app/views/projects/show.rhtml @@ -18,7 +18,7 @@ <% end %> <% @project.visible_custom_field_values.each do |custom_value| %> <% if !custom_value.value.blank? %> -
  • <%= custom_value.custom_field.name%>: <%=h show_value(custom_value) %>
  • +
  • <%=h custom_value.custom_field.name %>: <%=h show_value(custom_value) %>
  • <% end %> <% end %> @@ -28,7 +28,7 @@

    <%=l(:label_issue_tracking)%>