@@ -30,13 +30,13 @@ echo '<script type="text/javascript" src="'.$this->moduleWebroot.'/public/js/con
30
30
31
31
</div>
32
32
<span><?php echo $ this ->t ('Current used space: ' ); ?>
33
- <span id='hUsedSpaceValue'><?php echo $ this ->hUsedSpace ; ?> </span></span>
33
+ <span id='hUsedSpaceValue'><?php echo $ this ->escape ( $ this -> hUsedSpace ) ; ?> </span></span>
34
34
<br/>
35
35
<span><?php echo $ this ->t ('Total space: ' ); ?>
36
- <span id='hQuotaValue'><?php echo $ this ->hQuota ; ?> </span></span>
37
- <span style="display: none;" id="hFreeSpaceValue"><?php echo $ this ->hFreeSpace ; ?> </span>
38
- <span style="display: none;" id="quotaValue"><?php echo $ this ->quota ; ?> </span>
39
- <span style="display: none;" id="usedSpaceValue"><?php echo $ this ->usedSpace ; ?> </span>
36
+ <span id='hQuotaValue'><?php echo $ this ->escape ( $ this -> hQuota ) ; ?> </span></span>
37
+ <span style="display: none;" id="hFreeSpaceValue"><?php echo $ this ->escape ( $ this -> hFreeSpace ) ; ?> </span>
38
+ <span style="display: none;" id="quotaValue"><?php echo $ this ->escape ( $ this -> quota ) ; ?> </span>
39
+ <span style="display: none;" id="usedSpaceValue"><?php echo $ this ->escape ( $ this -> usedSpace ) ; ?> </span>
40
40
<div id='quotaChart' style="height: 200px; width: 400px; display: none;"></div>
41
41
<br/>
42
42
<?php
@@ -55,19 +55,19 @@ if ($this->isAdmin) {
55
55
$ value = 1 ;
56
56
foreach (array ('KB ' , 'MB ' , 'GB ' , 'TB ' ) as $ unit ) {
57
57
$ value *= 1024 ;
58
- echo '<option value=" ' .$ value .'" ' ;
58
+ echo '<option value=" ' .$ this -> escape ( $ value) .'" ' ;
59
59
if ($ this ->unitFormValue == $ unit ) {
60
60
echo ' selected="selected" ' ;
61
61
}
62
- echo '> ' .$ unit .'</option> ' ;
62
+ echo '> ' .$ this -> escape ( $ unit) .'</option> ' ;
63
63
}
64
64
?>
65
65
</select>
66
66
67
67
<div>
68
68
<?php echo $ this ->configForm ['submitQuota ' ]; ?>
69
69
</div>
70
- <input type="hidden" name="folderId" value="<?php echo $ this ->folder ->getKey (); ?> "/>
70
+ <input type="hidden" name="folderId" value="<?php echo $ this ->escape ( $ this -> folder ->getKey () ); ?> "/>
71
71
</form>
72
72
<?php
73
73
} ?>
0 commit comments