diff --git a/app/views/manage_products/_edit_info.html.erb b/app/views/manage_products/_edit_info.html.erb index 5505b94..997a35f 100644 --- a/app/views/manage_products/_edit_info.html.erb +++ b/app/views/manage_products/_edit_info.html.erb @@ -47,7 +47,7 @@ <%= button_to_function( :add, _('Add new qualifier'), - "new_qualifier_row('#product-qualifiers-list', '#{escape_javascript(select_qualifiers(@product))}', '#{escape_javascript(remove_qualifier_button)}')" + "new_qualifier_row('#product-qualifiers-list', '#{escape_javascript(CGI::escape_html(select_qualifiers(@product)))}', '#{escape_javascript(CGI::escape_html(remove_qualifier_button))}')" ) %> <%= hidden_field_tag "product[qualifiers_list][nil]" %> <% end %> -- libgit2 0.21.2