Welcome to the LimeSurvey Community Forum

Ask the community, share ideas, and connect with other LimeSurvey users!

Using html entities such as greater than or less than <> not parsing as text

  • cheeseburger
  • cheeseburger's Avatar Topic Author
  • Offline
  • Senior Member
  • Senior Member
More
1 year 15 hours ago #242844 by cheeseburger
Please help us help you and fill where relevant:
Your LimeSurvey version: 6.0.4+230427
Own server or LimeSurvey hosting: Own server
Survey theme/template: Extending Vanilla
==================
Hello, Please see the screen shot below for reference. We are using question of type "List (Dropdown)". Within its answer options, we have values such as "Burger > Pizza". When we save the question, the > symbol remains as typed. When we save and close the question, the symbol is converted to its html entity code. This code will then display within the LS control panel view and on the front end through the browser of the actual survey. 

We tried to open the html editor window and tried through the source mode. It continues to convert back to the code. 

Thanks for any help. 

Please Log in to join the conversation.

  • DenisChenu
  • DenisChenu's Avatar
  • Offline
  • LimeSurvey Community Team
  • LimeSurvey Community Team
More
11 months 4 weeks ago - 11 months 4 weeks ago #242864 by DenisChenu
&gt; and &lt; are the html entities for > and <

It shown as > and < in surtveyè.

Just preview question.

It's needed for XSS protection here.

[Edit] Seems there are an issue : please report with a sample survey. community.limesurvey.org/bug-tracker/

(sorry : don't read the  “on the front end through the browser of the actual survey” part)
 

Assistance on LimeSurvey forum and LimeSurvey core development are on my free time.
I'm not a LimeSurvey GmbH member, professional service on demand , plugin development .
I don't answer to private message.
Last edit: 11 months 4 weeks ago by DenisChenu.

Please Log in to join the conversation.

  • cheeseburger
  • cheeseburger's Avatar Topic Author
  • Offline
  • Senior Member
  • Senior Member
More
11 months 4 weeks ago #242887 by cheeseburger
Hi. Similar to the bug I posted a couple of days ago, I still can't post bugs. If you would be interested, please feel free to post this bug also. It was noted that the other bug (a third bug) regarding us not being able to log into the bug tracker is also being worked on. Thank you for your help.

Please Log in to join the conversation.

  • cheeseburger
  • cheeseburger's Avatar Topic Author
  • Offline
  • Senior Member
  • Senior Member
More
11 months 3 weeks ago #242992 by cheeseburger
Hi Denis, I wanted to follow up on this item: There is an outstanding bug that doesnt permit me to log in to the bug tracker. Tony had submitted my last bug on my behalf, would you be able to submit the bug in this thread for me? I apologize for any inconvenience but really appreciate the assist. Thank you!

Please Log in to join the conversation.

  • DenisChenu
  • DenisChenu's Avatar
  • Offline
  • LimeSurvey Community Team
  • LimeSurvey Community Team
More
11 months 3 weeks ago #242993 by DenisChenu
Can you send me the simple lss file with just one Single choice dropdown question ?

You use 3.X before ? I like to test fi it's OK in 3.X or not.

Assistance on LimeSurvey forum and LimeSurvey core development are on my free time.
I'm not a LimeSurvey GmbH member, professional service on demand , plugin development .
I don't answer to private message.

Please Log in to join the conversation.

  • tpartner
  • tpartner's Avatar
  • Offline
  • LimeSurvey Community Team
  • LimeSurvey Community Team
More
11 months 3 weeks ago #242994 by tpartner
I cannot reproduce this problem in 6.0.5.

Can you attach a small sample .lss?

Cheers,
Tony Partner

Solutions, code and workarounds presented in these forums are given without any warranty, implied or otherwise.

Please Log in to join the conversation.

  • cheeseburger
  • cheeseburger's Avatar Topic Author
  • Offline
  • Senior Member
  • Senior Member
More
11 months 3 weeks ago #243002 by cheeseburger
Denis/Tony - absolutely. Really appreciate you taking them time. Please see the attached. Thank you! 

File Attachment:

File Name: GreaterTha...Than.lss
File Size:20 KB

Please Log in to join the conversation.

  • cheeseburger
  • cheeseburger's Avatar Topic Author
  • Offline
  • Senior Member
  • Senior Member
More
11 months 3 weeks ago #243003 by cheeseburger
We will also update from 6.04 to 6.05 and see if the issue is no longer present. Thanks!
The following user(s) said Thank You: DenisChenu

Please Log in to join the conversation.

  • holch
  • holch's Avatar
  • Offline
  • LimeSurvey Community Team
  • LimeSurvey Community Team
More
11 months 3 weeks ago - 11 months 3 weeks ago #243011 by holch
Imported your survey in LS5 and it shows &gt; instead of >.

However, if I use > in the answer option, it just shows > like normal.

I answer at the LimeSurvey forum in my spare time, I'm not a LimeSurvey GmbH employee.
No support via private message.

Last edit: 11 months 3 weeks ago by holch.

Please Log in to join the conversation.

  • holch
  • holch's Avatar
  • Offline
  • LimeSurvey Community Team
  • LimeSurvey Community Team
More
11 months 3 weeks ago #243013 by holch
Now in LS6 something strange happens.

This is what I included to test:
 

And this is the result:
 

I answer at the LimeSurvey forum in my spare time, I'm not a LimeSurvey GmbH employee.
No support via private message.

Please Log in to join the conversation.

  • cheeseburger
  • cheeseburger's Avatar Topic Author
  • Offline
  • Senior Member
  • Senior Member
More
11 months 3 weeks ago #243015 by cheeseburger
Update: We updated LS to v6.05 and retried and the issue continues

Holch - yep, that's exactly our experience as well (as your screen shot shows).

Thanks everyone. Per Denis' post above, should we post to the bug tracker? If so, please would you mind posting on my behalf since I am not able to login to the bug tracker site.

Thanks!

Please Log in to join the conversation.

  • DenisChenu
  • DenisChenu's Avatar
  • Offline
  • LimeSurvey Community Team
  • LimeSurvey Community Team
More
11 months 3 weeks ago #243021 by DenisChenu

However, if I use > in the answer option, it just shows > like normal.
 
You can not use < or > in text if XSS is activated.

You need a non admin user with XSS activated to test.

I check with 3.X , 5.X and current master before reporting.

Assistance on LimeSurvey forum and LimeSurvey core development are on my free time.
I'm not a LimeSurvey GmbH member, professional service on demand , plugin development .
I don't answer to private message.

Please Log in to join the conversation.

Lime-years ahead

Online-surveys for every purse and purpose