diff --git a/app/call_flows/call_flows.php b/app/call_flows/call_flows.php index 63470be4a0..24ddc44680 100644 --- a/app/call_flows/call_flows.php +++ b/app/call_flows/call_flows.php @@ -122,7 +122,7 @@ echo " ".$text['title-call_flows']."\n"; echo "
\n"; echo " \n"; - echo " \n"; + echo " \n"; echo " \n"; echo " \n"; echo "
\n"; @@ -172,35 +172,35 @@ echo "\n"; echo " "; if ($row['call_flow_status'] != "false") { - echo $row['call_flow_label']; + echo escape($row['call_flow_label']); } else { - echo $row['call_flow_alternate_label']; + echo escape($row['call_flow_alternate_label']); } echo " \n"; echo " \n"; - //echo " ".$row['call_flow_name']." \n"; - echo " ".$row['call_flow_extension']." \n"; - echo " ".$row['call_flow_feature_code']." \n"; + //echo " ".escape($row['call_flow_name'])." \n"; + echo " ".escape($row['call_flow_extension'])." \n"; + echo " ".escape($row['call_flow_feature_code'])." \n"; if (permission_exists('call_flow_context')) { - echo " ".$row['call_flow_context']." \n"; + echo " ".escape($row['call_flow_context'])." \n"; } - //echo " ".$row['call_flow_pin_number']." \n"; - //echo " ".$row['call_flow_label']." \n"; - //echo " ".$row['call_flow_sound']." \n"; - //echo " ".$row['call_flow_app']." \n"; - //echo " ".$row['call_flow_data']." \n"; - //echo " ".$row['call_flow_alternate_label']." \n"; - //echo " ".$row['call_flow_alternate_sound']." \n"; - //echo " ".$row['call_flow_alternate_app']." \n"; - //echo " ".$row['call_flow_alternate_data']." \n"; - echo " ".$row['call_flow_description']." \n"; + //echo " ".escape($row['call_flow_pin_number'])." \n"; + //echo " ".escape($row['call_flow_label'])." \n"; + //echo " ".escape($row['call_flow_sound'])." \n"; + //echo " ".escape($row['call_flow_app'])." \n"; + //echo " ".escape($row['call_flow_data'])." \n"; + //echo " ".escape($row['call_flow_alternate_label'])." \n"; + //echo " ".escape($row['call_flow_alternate_sound'])." \n"; + //echo " ".escape($row['call_flow_alternate_app'])." \n"; + //echo " ".escape($row['call_flow_alternate_data'])." \n"; + echo " ".escape($row['call_flow_description'])." \n"; echo " "; if (permission_exists('call_flow_edit')) { - echo "$v_link_label_edit"; + echo "$v_link_label_edit"; } if (permission_exists('call_flow_delete')) { - echo "$v_link_label_delete"; + echo "$v_link_label_delete"; } echo " \n"; echo "\n";