diff --git a/lms/templates/certificates/_accomplishment-banner.html b/lms/templates/certificates/_accomplishment-banner.html index 2ca86733c3..eba7ee8d9c 100644 --- a/lms/templates/certificates/_accomplishment-banner.html +++ b/lms/templates/certificates/_accomplishment-banner.html @@ -40,7 +40,7 @@ from django.template.defaultfilters import escapejs
${accomplishment_banner_congrats}
- ${accomplishment_copy_name}
+ ${accomplishment_copy_name | h}
${accomplishment_copy_description_full}
@@ -86,7 +86,7 @@ course_mode_class = course_mode if course_mode else ''
${accomplishment_copy_username} @ ${platform_name}${accomplishment_copy_more_about}
+ ${accomplishment_copy_more_about | h}
@@ -96,7 +96,7 @@ course_mode_class = course_mode if course_mode else ''
${accomplishment_copy_name}
+ ${accomplishment_copy_name | h}
';
+ overlay_content = '' + value['name'] + " " + value['username'] + ' ';
$('.metrics-overlay-content tbody', metrics_overlay).append(overlay_content);
});
// If student list too long, append message to screen.
@@ -131,7 +131,7 @@ from django.template.defaultfilters import escapejs
$('.metrics-overlay-content thead', metrics_overlay).append(overlay_content);
$.each(response.results, function(index, value ){
- overlay_content = '' + _.escape(value['name']) + " " + _.escape(value['username']) + ' ';
+ overlay_content = '' + value['name'] + " " + value['username'] + " " + value['grade'] + " " + value['percent'] + ' ';
$('.metrics-overlay-content tbody', metrics_overlay).append(overlay_content);
});
// If student list too long, append message to screen.
diff --git a/lms/templates/verify_student/pay_and_verify.html b/lms/templates/verify_student/pay_and_verify.html
index 6c1882ff1d..7ea4f6ac27 100644
--- a/lms/templates/verify_student/pay_and_verify.html
+++ b/lms/templates/verify_student/pay_and_verify.html
@@ -59,7 +59,7 @@ from lms.djangoapps.verify_student.views import PayAndVerifyView
' + _.escape(value['name']) + " " + _.escape(value['username']) + " " + _.escape(value['grade']) + " " + _.escape(value['percent']) + '