diff --git a/htdocs/accountancy/admin/categories_list.php b/htdocs/accountancy/admin/categories_list.php index 68128630deb..cb987055cea 100644 --- a/htdocs/accountancy/admin/categories_list.php +++ b/htdocs/accountancy/admin/categories_list.php @@ -787,7 +787,7 @@ if ($id) { $class = 'tddict'; // Show value for field if ($showfield) { - print ''.$valuetoshow.''; + print ''.dol_escape_htmltag($valuetoshow).''; } } } diff --git a/htdocs/compta/resultat/result.php b/htdocs/compta/resultat/result.php index 67bc2d2e61f..467169230d0 100644 --- a/htdocs/compta/resultat/result.php +++ b/htdocs/compta/resultat/result.php @@ -1,7 +1,7 @@ * Copyright (C) 2016 Alexandre Spangaro - * Copyright (C) 2018 Laurent Destailleur + * Copyright (C) 2018-2020 Laurent Destailleur * Copyright (C) 2018 Frédéric France * * This program is free software; you can redistribute it and/or modify @@ -318,9 +318,9 @@ if ($modecompta == 'CREANCES-DETTES') { // Year NP print ''; - print $cat['code']; + print dol_escape_htmltag($cat['code']); print ''; - print $cat['label']; + print dol_escape_htmltag($cat['label']); print ''; $vars = array(); @@ -337,7 +337,7 @@ if ($modecompta == 'CREANCES-DETTES') { $r = dol_eval($result, 1); //var_dump($r); - print ''.price($r).''; + print ''.price($r).''; // Year N $code = $cat['code']; // code of categorie ('VTE', 'MAR', ...) @@ -355,7 +355,7 @@ if ($modecompta == 'CREANCES-DETTES') { //$r = $AccCat->calculate($result); $r = dol_eval($result, 1); - print ''.price($r).''; + print ''.price($r).''; $sommes[$code]['N'] += $r; // Detail by month @@ -369,7 +369,7 @@ if ($modecompta == 'CREANCES-DETTES') { //$r = $AccCat->calculate($result); $r = dol_eval($result, 1); - print ''.price($r).''; + print ''.price($r).''; $sommes[$code]['M'][$k] += $r; } } @@ -383,7 +383,7 @@ if ($modecompta == 'CREANCES-DETTES') { //$r = $AccCat->calculate($result); $r = dol_eval($result, 1); - print ''.price($r).''; + print ''.price($r).''; $sommes[$code]['M'][$k] += $r; } } @@ -471,12 +471,12 @@ if ($modecompta == 'CREANCES-DETTES') { // Column group print ''; - print $cat['code']; + print dol_escape_htmltag($cat['code']); print ''; // Label of group print ''; - print $cat['label']; + print dol_escape_htmltag($cat['label']); if (count($cpts) > 0) { // Show example of 5 first accounting accounts $i = 0; foreach ($cpts as $cpt) { @@ -489,7 +489,7 @@ if ($modecompta == 'CREANCES-DETTES') { } else { print ' ('; } - print $cpt['account_number']; + print dol_escape_htmltag($cpt['account_number']); $i++; } if ($i <= 5) {