diff --git a/course/lib.php b/course/lib.php index f2d90db832c..a58b86ad3c9 100644 --- a/course/lib.php +++ b/course/lib.php @@ -1516,8 +1516,9 @@ function print_section($course, $section, $mods, $modnamesused, $absolute=false, $textcss = ''; } - // Get on-click attribute value if specified - $onclick = $mod->get_on_click(); + // Get on-click attribute value if specified and decode the onclick - it + // has already been encoded for display (puke). + $onclick = htmlspecialchars_decode($mod->get_on_click(), ENT_QUOTES); $groupinglabel = ''; if (!empty($mod->groupingid) && has_capability('moodle/course:managegroups', context_course::instance($course->id))) { diff --git a/lib/navigationlib.php b/lib/navigationlib.php index 450f2664d71..a470f39d158 100644 --- a/lib/navigationlib.php +++ b/lib/navigationlib.php @@ -1922,7 +1922,7 @@ class global_navigation extends navigation_node { $propogrationhandler = 'e.halt();'; } // Decode the onclick - it has already been encoded for display (puke) - $onclick = htmlspecialchars_decode($activity->onclick); + $onclick = htmlspecialchars_decode($activity->onclick, ENT_QUOTES); // Build the JS function the click event will call $jscode = "function {$functionname}(e) { $propogrationhandler $onclick }"; $this->page->requires->js_init_code($jscode);