diff --git a/tools/profiling/Controller.php b/tools/profiling/Controller.php
index 7011ea222..1b55dd0dd 100644
--- a/tools/profiling/Controller.php
+++ b/tools/profiling/Controller.php
@@ -387,7 +387,7 @@ abstract class Controller extends ControllerCore
uasort($queries, 'prestashop_querytime_sort');
foreach ($queries as $data)
{
- echo $hr.'getTimeColor($data['time'] * 1000).'>'.round($data['time'] * 1000, 3).' ms '.$data['query'].'
in '.$data['file'].':'.$data['line'].'
';
+ echo $hr.'getTimeColor($data['time'] * 1000).'>'.round($data['time'] * 1000, 3).' ms '.htmlspecialchars($data['query'], ENT_NOQUOTES, 'utf-8', false).'
in '.$data['file'].':'.$data['line'].'
';
if (preg_match('/^\s*select\s+/i', $data['query']))
{
$explain = Db::getInstance()->executeS('explain '.$data['query']);