diff --git a/lib/questionlib.php b/lib/questionlib.php index 5e07530549f..90f6b22863b 100644 --- a/lib/questionlib.php +++ b/lib/questionlib.php @@ -645,8 +645,10 @@ function restore_question_state(&$question, &$state) { global $QTYPES; // initialise response to the value in the answer field + $state->answer = addslashes($state->answer); $state->responses = array('' => $state->answer); unset($state->answer); + $state->comment = isset($state->comment) ? addslashes($state->comment) : ''; // Set the changed field to false; any code which changes the // question session must set this to true and must increment diff --git a/question/type/essay/questiontype.php b/question/type/essay/questiontype.php index 82309608411..4846590da25 100644 --- a/question/type/essay/questiontype.php +++ b/question/type/essay/questiontype.php @@ -110,7 +110,7 @@ class question_essay_qtype extends default_questiontype { // get response value if (isset($state->responses[''])) { // security problem. responses[''] is never cleaned before it is sent to the db (I think) - $value = $state->responses['']; + $value = stripslashes_safe($state->responses['']); } else { $value = ""; } diff --git a/question/type/questiontype.php b/question/type/questiontype.php index 3bed76d117a..920638ab266 100644 --- a/question/type/questiontype.php +++ b/question/type/questiontype.php @@ -475,7 +475,7 @@ class default_questiontype { $grade .= $question->maxgrade; } - $comment = $state->comment; + $comment = stripslashes($state->comment); $commentlink = ''; if (isset($options->questioncommentlink)) { $strcomment = get_string('commentorgrade', 'quiz');