Fixed problem with slashes, bug 5177
This commit is contained in:
@@ -645,8 +645,10 @@ function restore_question_state(&$question, &$state) {
|
||||
global $QTYPES;
|
||||
|
||||
// initialise response to the value in the answer field
|
||||
$state->answer = addslashes($state->answer);
|
||||
$state->responses = array('' => $state->answer);
|
||||
unset($state->answer);
|
||||
$state->comment = isset($state->comment) ? addslashes($state->comment) : '';
|
||||
|
||||
// Set the changed field to false; any code which changes the
|
||||
// question session must set this to true and must increment
|
||||
|
||||
@@ -110,7 +110,7 @@ class question_essay_qtype extends default_questiontype {
|
||||
// get response value
|
||||
if (isset($state->responses[''])) {
|
||||
// security problem. responses[''] is never cleaned before it is sent to the db (I think)
|
||||
$value = $state->responses[''];
|
||||
$value = stripslashes_safe($state->responses['']);
|
||||
} else {
|
||||
$value = "";
|
||||
}
|
||||
|
||||
@@ -475,7 +475,7 @@ class default_questiontype {
|
||||
$grade .= $question->maxgrade;
|
||||
}
|
||||
|
||||
$comment = $state->comment;
|
||||
$comment = stripslashes($state->comment);
|
||||
$commentlink = '';
|
||||
if (isset($options->questioncommentlink)) {
|
||||
$strcomment = get_string('commentorgrade', 'quiz');
|
||||
|
||||
Reference in New Issue
Block a user