diff --git a/htdocs/societe/list.php b/htdocs/societe/list.php
index 0a3e9207a96..48cc882c052 100644
--- a/htdocs/societe/list.php
+++ b/htdocs/societe/list.php
@@ -1405,7 +1405,7 @@ while ($i < min($num, $limit)) {
}
if (!empty($arrayfields['s.name_alias']['checked'])) {
print '
';
- print $companystatic->name_alias;
+ print dol_escape_htmltag($companystatic->name_alias);
print " | \n";
if (!$i) {
$totalarray['nbfield']++;
@@ -1413,70 +1413,70 @@ while ($i < min($num, $limit)) {
}
// Barcode
if (!empty($arrayfields['s.barcode']['checked'])) {
- print ''.$obj->barcode.' | ';
+ print ''.dol_escape_htmltag($obj->barcode).' | ';
if (!$i) {
$totalarray['nbfield']++;
}
}
// Customer code
if (!empty($arrayfields['s.code_client']['checked'])) {
- print ''.$obj->code_client.' | ';
+ print ''.dol_escape_htmltag($obj->code_client).' | ';
if (!$i) {
$totalarray['nbfield']++;
}
}
// Supplier code
if (!empty($arrayfields['s.code_fournisseur']['checked'])) {
- print ''.$obj->code_fournisseur.' | ';
+ print ''.dol_escape_htmltag($obj->code_fournisseur).' | ';
if (!$i) {
$totalarray['nbfield']++;
}
}
// Account customer code
if (!empty($arrayfields['s.code_compta']['checked'])) {
- print ''.$obj->code_compta.' | ';
+ print ''.dol_escape_htmltag($obj->code_compta).' | ';
if (!$i) {
$totalarray['nbfield']++;
}
}
// Account supplier code
if (!empty($arrayfields['s.code_compta_fournisseur']['checked'])) {
- print ''.$obj->code_compta_fournisseur.' | ';
+ print ''.dol_escape_htmltag($obj->code_compta_fournisseur).' | ';
if (!$i) {
$totalarray['nbfield']++;
}
}
// Address
if (!empty($arrayfields['s.address']['checked'])) {
- print ''.$obj->address.' | ';
+ print ''.dol_escape_htmltag($obj->address).' | ';
if (!$i) {
$totalarray['nbfield']++;
}
}
// Zip
if (!empty($arrayfields['s.zip']['checked'])) {
- print "".$obj->zip." | \n";
+ print "".dol_escape_htmltag($obj->zip)." | \n";
if (!$i) {
$totalarray['nbfield']++;
}
}
// Town
if (!empty($arrayfields['s.town']['checked'])) {
- print "".$obj->town." | \n";
+ print ''.dol_escape_htmltag($obj->town)." | \n";
if (!$i) {
$totalarray['nbfield']++;
}
}
// State
if (!empty($arrayfields['state.nom']['checked'])) {
- print "".$obj->state_name." | \n";
+ print "".dol_escape_htmltag($obj->state_name)." | \n";
if (!$i) {
$totalarray['nbfield']++;
}
}
// Region
if (!empty($arrayfields['region.nom']['checked'])) {
- print "".$obj->region_name." | \n";
+ print "".dol_escape_htmltag($obj->region_name)." | \n";
if (!$i) {
$totalarray['nbfield']++;
}