diff --git a/app/music_on_hold/music_on_hold.php b/app/music_on_hold/music_on_hold.php index e83268d389..6c4dc88554 100644 --- a/app/music_on_hold/music_on_hold.php +++ b/app/music_on_hold/music_on_hold.php @@ -383,7 +383,7 @@ if (strlen($row['domain_uuid']) == 0) { if (strlen($row['music_on_hold_rate']) == 0) { $option_name = $row['music_on_hold_name']; } if (strlen($row['music_on_hold_rate']) > 0) { $option_name = $row['music_on_hold_name'] .'/'.$row['music_on_hold_rate']; } - echo " \n"; + echo " \n"; } } echo " \n"; @@ -395,7 +395,7 @@ if (strlen($row['domain_uuid']) > 0) { if (strlen($row['music_on_hold_rate']) == 0) { $option_name = $row['music_on_hold_name']; } if (strlen($row['music_on_hold_rate']) > 0) { $option_name = $row['music_on_hold_name'] .'/'.$row['music_on_hold_rate']; } - echo " \n"; + echo " \n"; } } if (permission_exists('music_on_hold_domain')) { @@ -489,7 +489,7 @@ if ($previous_name != $music_on_hold_name) { echo "
\n"; echo "\n"; - echo " ".$music_on_hold_name.""; + echo " ".escape($music_on_hold_name).""; if ($row['domain_uuid'] == null) { echo "  - ".$text['label-global']."\n"; } @@ -581,14 +581,14 @@ echo "\n"; $tr_link = "href=\"javascript:recording_play('".$row_uuid."');\""; echo "\n"; - echo " ".str_replace('_', '_​', $stream_file)."\n"; + echo " ".escape($stream_file)."\n"; echo " "; - echo ""; + echo ""; echo "".$v_link_label_play.""; echo "".$v_link_label_stop.""; echo " \n"; - echo " ".$stream_file_size."\n"; - echo " ".$stream_file_date."\n"; + echo " ".escape($stream_file_size)."\n"; + echo " ".escape($stream_file_date)."\n"; echo " \n"; echo "".$v_link_label_download.""; if ( ($domain_uuid == '' && permission_exists('music_on_hold_domain')) || ($domain_uuid != '' && permission_exists('music_on_hold_delete')) ) {