',
'
">
',
- '
<%= name %>
',
+ '
<%= Common.Utils.String.htmlEncode(name) %>
',
'
<%= scopeName %>
',
'
<%= range %>
',
'<% if (lock) { %>',
diff --git a/apps/spreadsheeteditor/main/app/view/NamedRangePasteDlg.js b/apps/spreadsheeteditor/main/app/view/NamedRangePasteDlg.js
index a977ac207..50fc84325 100644
--- a/apps/spreadsheeteditor/main/app/view/NamedRangePasteDlg.js
+++ b/apps/spreadsheeteditor/main/app/view/NamedRangePasteDlg.js
@@ -95,7 +95,7 @@ define([
'
',
'
',
'
">
',
- '
<%= name %>
',
+ '
<%= Common.Utils.String.htmlEncode(name) %>
',
'
',
'
'
].join(''))
diff --git a/apps/spreadsheeteditor/main/app/view/ViewManagerDlg.js b/apps/spreadsheeteditor/main/app/view/ViewManagerDlg.js
index d41d1b08b..f606e72ec 100644
--- a/apps/spreadsheeteditor/main/app/view/ViewManagerDlg.js
+++ b/apps/spreadsheeteditor/main/app/view/ViewManagerDlg.js
@@ -118,7 +118,7 @@ define([
template: _.template(['
'].join('')),
itemTemplate: _.template([
'
',
- '
<%= name %>
',
+ '
<%= Common.Utils.String.htmlEncode(name) %>
',
'<% if (lock) { %>',
'
<%=lockuser%>
',
'<% } %>',