diff --git a/htdocs/opensurvey/adminstuds_preview.php b/htdocs/opensurvey/adminstuds_preview.php
index 9307add0f94..13767fe086f 100644
--- a/htdocs/opensurvey/adminstuds_preview.php
+++ b/htdocs/opensurvey/adminstuds_preview.php
@@ -708,7 +708,7 @@ else
for ($i = 0; isset($toutsujet[$i]); $i++)
{
$tmp=explode('@',$toutsujet[$i]);
- print '
'.$tmp[0].' | '."\n";
+ print ''.htmlentities($tmp[0]).' | '."\n";
}
print ''.img_picto('',dol_buildpath('/opensurvey/img/add-16.png',1),'',1).' | '."\n";
diff --git a/htdocs/opensurvey/list.php b/htdocs/opensurvey/list.php
index b0502707669..1ecd93265de 100644
--- a/htdocs/opensurvey/list.php
+++ b/htdocs/opensurvey/list.php
@@ -117,11 +117,11 @@ while ($i < min($num,$limit))
print '';
print '| ';
print ''.img_picto('','object_opensurvey').' '.$obj->id_sondage.'';
- print ' | '.$obj->titre.' | ';
+ print ' | '.htmlentities($obj->titre).' | ';
$type=($obj->format=='A' || $obj->format=='A+')?'classic':'date';
print img_picto('',dol_buildpath('/opensurvey/img/'.($type == 'classic'?'chart-32.png':'calendar-32.png'),1),'width="16"',1);
print ' '.$langs->trans($type=='classic'?"TypeClassic":"TypeDate");
- print ' | '.$obj->nom_admin.' | ';
+ print ''.htmlentities($obj->nom_admin).' | ';
print ''.dol_print_date($db->jdate($obj->date_fin),'day');
if ($db->jdate($obj->date_fin) < time()) { print ' '.img_warning(); }
|