<% %>
<% if @voter.election.shortdesc %>
- <h1><%= @voter.election.shortdesc %></h1>
+ <h1><%=h @voter.election.shortdesc %></h1>
<% else %>
<h1>QuickVote</h1>
<% end %>
<% if @voter.election.longdesc %>
<p><strong>Description:</strong></p>
- <blockquote><%= @voter.election.longdesc %></blockquote>
+ <blockquote><%=h @voter.election.longdesc %></blockquote>
<h2>Vote</h2>
<% end %>
<ol id="rankings-list">
<% for ranking in @voter.vote.rankings %>
<li class="moveable" id="ranking_<%= ranking.candidate.id %>">
- <%= ranking.candidate.name.capitalize %></li>
+ <%=h ranking.candidate.name.capitalize %></li>
<% end %>
</ol>
</div>