Fixed allowing for execution of arbitrary Javascript in student response.

ORA-256
This commit is contained in:
Waheed Ahmed
2014-01-21 18:51:25 +05:00
parent a077dc815c
commit d12e7e8877

View File

@@ -368,6 +368,7 @@ class @CombinedOpenEnded
@rub.initialize(@location)
@child_state = 'assessing'
@find_assessment_elements()
@answer_area.val(response.student_response)
@rebind()
answer_area_div = @$(@answer_area_div_sel)
answer_area_div.html(response.student_response)