Commit 158217c5 authored by Vincent Pelletier's avatar Vincent Pelletier

Escape render_items items text (used in ListField, for example).


git-svn-id: https://svn.erp5.org/repos/public/erp5/trunk@20944 20353a03-c40f-0410-a6d1-a30d3c3de9de
parent f7d8bdae
......@@ -611,14 +611,14 @@ def SingleItemsWidget_render_items(self, field, key, value, REQUEST):
if item_value == value and not selected_found:
rendered_item = self.render_selected_item(item_text,
rendered_item = self.render_selected_item(escape(item_text),
item_value,
key,
css_class,
extra_item)
selected_found = 1
else:
rendered_item = self.render_item(item_text,
rendered_item = self.render_item(escape(item_text),
item_value,
key,
css_class,
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment