diff --git a/app/code/Magento/Backend/view/adminhtml/templates/system/search.phtml b/app/code/Magento/Backend/view/adminhtml/templates/system/search.phtml index b841486dea6dc90696312fadd51fe063d33cb1ce..c472c6827033bd8baef4785f695c7be971dc456e 100644 --- a/app/code/Magento/Backend/view/adminhtml/templates/system/search.phtml +++ b/app/code/Magento/Backend/view/adminhtml/templates/system/search.phtml @@ -17,7 +17,7 @@ class="search-global-input" id="search-global" name="query" - data-mage-init='<?php echo $block->escapeHtml($this->helper('Magento\Framework\Json\Helper\Data')->jsonEncode($block->getWidgetInitOptions()))?>'> + data-mage-init='<?php /* noEscape */ echo $this->helper('Magento\Framework\Json\Helper\Data')->jsonEncode($block->getWidgetInitOptions()) ?>'> <button type="submit" class="search-global-action" diff --git a/app/code/Magento/GoogleAnalytics/Block/Ga.php b/app/code/Magento/GoogleAnalytics/Block/Ga.php index 32fd8a8584e446053ac74aa056b9bf58ca2c7ab3..eafc1121ea6cd1928daccadb9682ec9235b2952d 100644 --- a/app/code/Magento/GoogleAnalytics/Block/Ga.php +++ b/app/code/Magento/GoogleAnalytics/Block/Ga.php @@ -77,12 +77,11 @@ class Ga extends \Magento\Framework\View\Element\Template $pageName = trim($this->getPageName()); $optPageURL = ''; if ($pageName && substr($pageName, 0, 1) == '/' && strlen($pageName) > 1) { - $optPageURL = ", '{$this->escapeJs($pageName)}'"; + $optPageURL = ", '" . htmlspecialchars($pageName, ENT_COMPAT, 'UTF-8', false) . "'"; } - return "\nga('create', '{$this->escapeJs( - $accountId - )}', 'auto');\nga('send', 'pageview'{$optPageURL});\n"; + return "\nga('create', '" . htmlspecialchars($accountId, ENT_COMPAT, 'UTF-8', false) + . ", 'auto');\nga('send', 'pageview'{$optPageURL});\n"; } /**