=== modified file 'dhis-2/dhis-web/dhis-web-caseentry/src/main/webapp/dhis-web-caseentry/javascript/commons.js' --- dhis-2/dhis-web/dhis-web-caseentry/src/main/webapp/dhis-web-caseentry/javascript/commons.js 2011-12-21 09:21:08 +0000 +++ dhis-2/dhis-web/dhis-web-caseentry/src/main/webapp/dhis-web-caseentry/javascript/commons.js 2012-02-09 03:38:44 +0000 @@ -87,7 +87,7 @@ } else if( $(this).attr('type') != 'button' ) { - params += elementId + "="+ jQuery(this).val() + "&"; + params += elementId + "="+ htmlEncode(jQuery(this).val()) + "&"; } });