diff --git a/app/conference_controls/conference_controls.php b/app/conference_controls/conference_controls.php
index b304440ad3..86b194932e 100644
--- a/app/conference_controls/conference_controls.php
+++ b/app/conference_controls/conference_controls.php
@@ -82,7 +82,7 @@
echo "
".$text['title-conference_controls']." | \n";
echo " \n";
@@ -115,15 +115,15 @@
$tr_link = "href='conference_control_edit.php?id=".$row['conference_control_uuid']."'";
}
echo "\n";
- echo " | ".$row['control_name']." | \n";
- echo " ".$row['control_enabled']." | \n";
- echo " ".$row['control_description']." | \n";
+ echo " ".escape($row['control_name'])." | \n";
+ echo " ".escape($row['control_enabled'])." | \n";
+ echo " ".escape($row['control_description'])." | \n";
echo " ";
if (permission_exists('conference_control_edit')) {
- echo "$v_link_label_edit";
+ echo "$v_link_label_edit";
}
if (permission_exists('conference_control_delete')) {
- echo "$v_link_label_delete";
+ echo "$v_link_label_delete";
}
echo " | \n";
echo "
\n";