diff --git a/components/project_management/build.xml b/components/project_management/build.xml
index 57acf7217..65eae72af 100644
--- a/components/project_management/build.xml
+++ b/components/project_management/build.xml
@@ -143,6 +143,7 @@
@@ -5985,13 +5986,15 @@ private void createProjectProperties(Long projectId, Project project, Map idValu for (Iterator it = idValueMap.entrySet().iterator(); it.hasNext();) { Entry entry = (Entry) it.next(); + Long key = (Long) entry.getKey(); + String value = (String) entry.getValue(); + value = Encode.forHtml(value); // insert the project property into database - Object[] queryArgs = new Object[] {projectId, entry.getKey(), - entry.getValue(), operator, operator }; + Object[] queryArgs = new Object[] {projectId, key, + value, operator, operator }; Helper.doDMLQuery(preparedStatement, queryArgs); - auditProjectInfo(conn, projectId, project, AUDIT_CREATE_TYPE, (Long) entry.getKey(), - (String) entry.getValue()); + auditProjectInfo(conn, projectId, project, AUDIT_CREATE_TYPE, key, value); } } catch (SQLException e) {