diff --git a/application/views/approval_chain_manager.xhtml b/application/views/approval_chain_manager.xhtml index 0687ae60ff0830b51f0c52f98740fc97b0dc7d54..294f8e3dc96ac20cf9b2a222c5f83c7f8278abb8 100644 --- a/application/views/approval_chain_manager.xhtml +++ b/application/views/approval_chain_manager.xhtml @@ -9,7 +9,7 @@ <?php foreach ($this->approvalChains as $approvalChain) { ?> <li> <a href="/ApprovalChainManager/EditChain/<?php echo $approvalChain->getPrimaryKey(); ?>"> - <?php echo $approvalChain->name; ?> + <?php echo htmlspecialchars($approvalChain->name); ?> </a> </li> <?php } ?> diff --git a/application/views/home.xhtml b/application/views/home.xhtml index 83bd648dbf0a16ca4fad019a7c28d45be8586d60..01948678298733f67a02e2fe7db06d5516e8a9ac 100755 --- a/application/views/home.xhtml +++ b/application/views/home.xhtml @@ -130,7 +130,7 @@ </td> <td><?php echo $originalCourse->getHomeCollege()->name; ?></td> <td><?php echo $request->type->name; ?></td> - <td><?php echo $request->getCurrentApprovalBody()->name; ?></td> + <td><?php echo htmlspecialchars($request->getCurrentApprovalBody()->name); ?></td> <td> <?php if ($request->complete == 'yes') { @@ -138,7 +138,8 @@ } else { echo $request->getCurrentAction()->name; } - ?> </td> + ?> + </td> <td> <a href="/Request/View/<?php echo $request->getPrimaryKey(); ?>">View</a> <a href="/Request/Load/<?php echo $request->getPrimaryKey(); ?>">Edit</a>