From 2e29cebf39146412d31ea09aa097d23f3f53ca72 Mon Sep 17 00:00:00 2001 From: FusionPBX Date: Tue, 5 Jun 2018 18:46:51 -0600 Subject: [PATCH] Update voicemails.php --- app/voicemails/voicemails.php | 21 +++++++++++---------- 1 file changed, 11 insertions(+), 10 deletions(-) diff --git a/app/voicemails/voicemails.php b/app/voicemails/voicemails.php index 9e069316f5..bb3f96eb1b 100644 --- a/app/voicemails/voicemails.php +++ b/app/voicemails/voicemails.php @@ -148,7 +148,7 @@ echo " \n"; echo " \n"; echo "
\n"; - echo " "; + echo " "; echo " "; echo "
\n"; echo " \n"; @@ -186,28 +186,28 @@ if ($num_rows > 0) { foreach($voicemails as $row) { - $tr_link = (permission_exists('voicemail_edit')) ? "href='voicemail_edit.php?id=".$row['voicemail_uuid']."'" : null; + $tr_link = (permission_exists('voicemail_edit')) ? "href='voicemail_edit.php?id=".escape($row['voicemail_uuid'])."'" : null; echo "\n"; if (permission_exists('voicemail_delete')) { echo " "; - echo " "; + echo " "; echo " "; $vm_ids[] = 'checkbox_'.$row['voicemail_uuid']; } echo " "; if (permission_exists('voicemail_edit')) { - echo "".$row['voicemail_id'].""; + echo "".escape($row['voicemail_id']).""; } else { - echo $row['voicemail_id']; + echo escape($row['voicemail_id']); } echo " \n"; - echo " ".$row['voicemail_mail_to']." \n"; + echo " ".escape($row['voicemail_mail_to'])." \n"; echo " ".(($row['voicemail_file'] == 'attach') ? $text['label-true'] : $text['label-false'])."\n"; - echo " ".ucwords($row['voicemail_local_after_email'])." \n"; + echo " ".ucwords(escape($row['voicemail_local_after_email']))." \n"; echo " \n"; if (permission_exists('voicemail_message_view')) { - echo " ".$text['label-messages']."  \n"; + echo " ".$text['label-messages']."  \n"; } if (permission_exists('voicemail_greeting_view')) { echo " ".$text['label-greetings']."\n"; @@ -218,10 +218,10 @@ if (permission_exists('voicemail_edit') || permission_exists('voicemail_delete')) { echo " "; if (permission_exists('voicemail_edit')) { - echo "".$v_link_label_edit.""; + echo "".$v_link_label_edit.""; } if (permission_exists('voicemail_delete')) { - echo "".$v_link_label_delete.""; + echo "".$v_link_label_delete.""; } echo " \n"; } @@ -276,4 +276,5 @@ //include the footer require_once "resources/footer.php"; + ?>