diff --git a/modules/admin/admin.admin.view.php b/modules/admin/admin.admin.view.php index a738c66f7..73a8c480e 100644 --- a/modules/admin/admin.admin.view.php +++ b/modules/admin/admin.admin.view.php @@ -250,6 +250,8 @@ $args->list_count = 5;; $output = $oDocumentModel->getDocumentList($args, false, false, $columnList); Context::set('latestDocumentList', $output->data); + $security = new Security(); + $security->encodeHTML('latestDocumentList..variables.nick_name'); unset($args, $output, $columnList); // Latest Comment diff --git a/modules/member/member.admin.view.php b/modules/member/member.admin.view.php index 9345aaad1..9aee2d108 100644 --- a/modules/member/member.admin.view.php +++ b/modules/member/member.admin.view.php @@ -142,7 +142,7 @@ $security = new Security(); $security->encodeHTML('member_config..'); - $security->encodeHTML('member_info.user_name','member_info.description','member_info.group_list..'); + $security->encodeHTML('memberInfo.user_name', 'memberInfo.nick_name', 'memberInfo.description','memberInfo.group_list..'); $security->encodeHTML('extend_form_list...'); $this->setTemplateFile('member_info'); diff --git a/modules/member/tpl/member_info.html b/modules/member/tpl/member_info.html index 50e6b9c1b..8844a1b76 100644 --- a/modules/member/tpl/member_info.html +++ b/modules/member/tpl/member_info.html @@ -21,19 +21,19 @@ {@$title = $extend_form_list[$formInfo->member_join_form_srl]->column_title} {@$orgValue = $extend_form_list[$formInfo->member_join_form_srl]->value} - {@$value = htmlspecialchars($orgValue[0])} + {@$value = $orgValue[0]} - - {@$value .= htmlspecialchars($orgValue[1])} + {@$value .= $orgValue[1]} - - {@$value .= htmlspecialchars($orgValue[2])} + {@$value .= $orgValue[2]} - {@$value = htmlspecialchars($orgValue[0])}
{@$value .= htmlspecialchars($orgValue[1])} + {@$value = $orgValue[0]}
{@$value .= $orgValue[1]} - {@$value = htmlspecialchars(implode(", ",$orgValue))} + {@$value = implode(", ",$orgValue)} {@$value = zdate($orgValue, "Y-m-d")} - {@$value = nl2br(htmlspecialchars($orgValue))} + {@$value = nl2br($orgValue)}