diff --git a/modules/comment/comment.controller.php b/modules/comment/comment.controller.php index 37b8360a5..64105c65f 100644 --- a/modules/comment/comment.controller.php +++ b/modules/comment/comment.controller.php @@ -206,7 +206,7 @@ $obj->content = preg_replace('!<\!--(Before|After)(Document|Comment)\(([0-9]+),([0-9]+)\)-->!is', '', $obj->content); if(Mobile::isFromMobilePhone()) { - $obj->content = nl2br(htmlspecialchars($obj->content)); + $obj->content = nl2br($obj->content); } if(!$obj->regdate) $obj->regdate = date("YmdHis"); // remove iframe and script if not a top administrator on the session. diff --git a/modules/document/document.controller.php b/modules/document/document.controller.php index 4bac3de0a..27f4e2a8e 100644 --- a/modules/document/document.controller.php +++ b/modules/document/document.controller.php @@ -235,7 +235,7 @@ class documentController extends document { $obj->content = preg_replace('!<\!--(Before|After)(Document|Comment)\(([0-9]+),([0-9]+)\)-->!is', '', $obj->content); if(Mobile::isFromMobilePhone()) { - $obj->content = nl2br(htmlspecialchars($obj->content)); + $obj->content = nl2br($obj->content); } // Remove iframe and script if not a top adminisrator in the session. if($logged_info->is_admin != 'Y') $obj->content = removeHackTag($obj->content);