diff --git a/htdocs/contact/fiche.php b/htdocs/contact/fiche.php index 2e28c7e2a5c..6a3ee5b2bcd 100644 --- a/htdocs/contact/fiche.php +++ b/htdocs/contact/fiche.php @@ -385,12 +385,13 @@ else }); $("#copyaddressfromsoc").click(function() { - $(\'textarea[name="address"]\').text("'.addslashes($objsoc->address).'"); - $(\'input[name="zipcode"]\').val("'.addslashes($objsoc->zip).'"); - $(\'input[name="town"]\').val("'.addslashes($objsoc->town).'"); - $(\'select[name="country_id"]\').val("'.addslashes($objsoc->country_id).'"); - $(\'select[name="state_id"]\').val("'.addslashes($objsoc->state_id).'"); - }); + $(\'textarea[name="address"]\').text("'.dol_escape_js($objsoc->address).'"); + $(\'input[name="zipcode"]\').val("'.dol_escape_js($objsoc->zip).'"); + $(\'input[name="town"]\').val("'.dol_escape_js($objsoc->town).'"); + $(\'select[name="country_id"]\').val("'.dol_escape_js($objsoc->country_id).'"); + $(\'select[name="state_id"]\').val("'.dol_escape_js($objsoc->state_id).'"); + $(\'input[name="email"]\').val("'.dol_escape_js($objsoc->email).'"); + }); })'."\n"; print ''."\n"; } @@ -482,16 +483,16 @@ else // Phone / Fax if (($objsoc->typent_code == 'TE_PRIVATE' || ! empty($conf->global->CONTACT_USE_COMPANY_ADDRESS)) && dol_strlen(trim($object->phone_pro)) == 0) $object->phone_pro = $objsoc->tel; // Predefined with third party - print '