diff --git a/app/views/submissions/show.html.erb b/app/views/submissions/show.html.erb index bc7eca555..5011e02b9 100644 --- a/app/views/submissions/show.html.erb +++ b/app/views/submissions/show.html.erb @@ -154,7 +154,7 @@
Reason: - <%= simple_format(submitter.submission_events.find_by(event_type: :decline_form).data['reason']) %> + <%= simple_format(h(submitter.submission_events.find_by(event_type: :decline_form).data['reason'])) %>
<% end %> diff --git a/app/views/submitter_mailer/declined_email.html.erb b/app/views/submitter_mailer/declined_email.html.erb index 382390923..24d6f9196 100644 --- a/app/views/submitter_mailer/declined_email.html.erb +++ b/app/views/submitter_mailer/declined_email.html.erb @@ -1,4 +1,4 @@

<%= t('hi_there') %>,

<%= t('name_declined_by_submitter_with_the_following_reason', name: @submitter.submission.template.name, submitter: @submitter.name || @submitter.email || @submitter.phone) %>

-<%= simple_format(@submitter.submission_events.find_by(event_type: :decline_form).data['reason']) %> +<%= simple_format(h(@submitter.submission_events.find_by(event_type: :decline_form).data['reason'])) %>

<%= link_to t('view'), submission_url(@submitter.submission) %>