diff --git a/htdocs/societe/list.php b/htdocs/societe/list.php index 0a3e9207a96..48cc882c052 100644 --- a/htdocs/societe/list.php +++ b/htdocs/societe/list.php @@ -1405,7 +1405,7 @@ while ($i < min($num, $limit)) { } if (!empty($arrayfields['s.name_alias']['checked'])) { print ''; - print $companystatic->name_alias; + print dol_escape_htmltag($companystatic->name_alias); print "\n"; if (!$i) { $totalarray['nbfield']++; @@ -1413,70 +1413,70 @@ while ($i < min($num, $limit)) { } // Barcode if (!empty($arrayfields['s.barcode']['checked'])) { - print ''.$obj->barcode.''; + print ''.dol_escape_htmltag($obj->barcode).''; if (!$i) { $totalarray['nbfield']++; } } // Customer code if (!empty($arrayfields['s.code_client']['checked'])) { - print ''.$obj->code_client.''; + print ''.dol_escape_htmltag($obj->code_client).''; if (!$i) { $totalarray['nbfield']++; } } // Supplier code if (!empty($arrayfields['s.code_fournisseur']['checked'])) { - print ''.$obj->code_fournisseur.''; + print ''.dol_escape_htmltag($obj->code_fournisseur).''; if (!$i) { $totalarray['nbfield']++; } } // Account customer code if (!empty($arrayfields['s.code_compta']['checked'])) { - print ''.$obj->code_compta.''; + print ''.dol_escape_htmltag($obj->code_compta).''; if (!$i) { $totalarray['nbfield']++; } } // Account supplier code if (!empty($arrayfields['s.code_compta_fournisseur']['checked'])) { - print ''.$obj->code_compta_fournisseur.''; + print ''.dol_escape_htmltag($obj->code_compta_fournisseur).''; if (!$i) { $totalarray['nbfield']++; } } // Address if (!empty($arrayfields['s.address']['checked'])) { - print ''.$obj->address.''; + print ''.dol_escape_htmltag($obj->address).''; if (!$i) { $totalarray['nbfield']++; } } // Zip if (!empty($arrayfields['s.zip']['checked'])) { - print "".$obj->zip."\n"; + print "".dol_escape_htmltag($obj->zip)."\n"; if (!$i) { $totalarray['nbfield']++; } } // Town if (!empty($arrayfields['s.town']['checked'])) { - print "".$obj->town."\n"; + print ''.dol_escape_htmltag($obj->town)."\n"; if (!$i) { $totalarray['nbfield']++; } } // State if (!empty($arrayfields['state.nom']['checked'])) { - print "".$obj->state_name."\n"; + print "".dol_escape_htmltag($obj->state_name)."\n"; if (!$i) { $totalarray['nbfield']++; } } // Region if (!empty($arrayfields['region.nom']['checked'])) { - print "".$obj->region_name."\n"; + print "".dol_escape_htmltag($obj->region_name)."\n"; if (!$i) { $totalarray['nbfield']++; }