The Checkmarx scanner is flagging "naked" (e.g. unencoded) merge-fields in a javascript context, so the following will quiet the scanner:
確定! 回上一頁