diff --git a/app/email_templates/email_templates.php b/app/email_templates/email_templates.php index 6b84ce4f39..ea7f299e59 100644 --- a/app/email_templates/email_templates.php +++ b/app/email_templates/email_templates.php @@ -150,8 +150,8 @@ echo " function checkbox_toggle(item) {\n"; echo " var inputs = document.getElementsByTagName(\"input\");\n"; echo " for (var i = 0, max = inputs.length; i < max; i++) {\n"; - echo " if (inputs[i].type === 'checkbox') {\n"; - echo " if (document.getElementById('checkbox_all').checked == true) {\n"; + echo " if (inputs[i].type === 'checkbox') {\n"; + echo " if (document.getElementById('checkbox_all').checked == true) {\n"; echo " inputs[i].checked = true;\n"; echo " }\n"; echo " else {\n"; @@ -176,7 +176,7 @@ echo " \n"; } } - echo " \n"; + echo " \n"; echo " \n"; echo " \n"; echo " \n"; @@ -213,12 +213,12 @@ $x = 0; foreach($result as $row) { if (permission_exists('email_template_edit')) { - $tr_link = "href='email_template_edit.php?id=".$row['email_template_uuid']."'"; + $tr_link = "href='email_template_edit.php?id=".escape($row['email_template_uuid'])."'"; } echo "\n"; echo " \n"; echo " \n"; - echo " \n"; + echo " \n"; echo " \n"; if ($_GET['show'] == "all" && permission_exists('email_template_all')) { if (strlen($_SESSION['domains'][$row['domain_uuid']]['domain_name']) > 0) { @@ -227,20 +227,20 @@ else { $domain = $text['label-global']; } - echo " ".$domain."\n"; + echo " ".escape($domain)."\n"; } - echo " ".$row['template_language']." \n"; - echo " ".$row['template_category']." \n"; - echo " ".$row['template_subcategory']." \n"; - //echo " ".$row['template_subject']." \n"; - //echo " ".$row['template_body']." \n"; - //echo " ".$row['domain_uuid']." \n"; - echo " ".$row['template_type']." \n"; - echo " ".$row['template_enabled']." \n"; - echo " ".$row['template_description']." \n"; + echo " ".escape($row['template_language'])." \n"; + echo " ".escape($row['template_category'])." \n"; + echo " ".escape($row['template_subcategory'])." \n"; + //echo " ".escape($row['template_subject'])." \n"; + //echo " ".escape($row['template_body'])." \n"; + //echo " ".escape($row['domain_uuid'])." \n"; + echo " ".escape($row['template_type'])." \n"; + echo " ".escape($row['template_enabled'])." \n"; + echo " ".escape($row['template_description'])." \n"; echo " "; if (permission_exists('email_template_edit')) { - echo "$v_link_label_edit"; + echo "$v_link_label_edit"; } if (permission_exists('email_template_delete')) { echo "";