diff --git a/core/apps/apps.php b/core/apps/apps.php index 5eeeefa429..8deb5170cc 100644 --- a/core/apps/apps.php +++ b/core/apps/apps.php @@ -97,13 +97,13 @@ $row['$description'] = $description; /* - $tr_link = (permission_exists('app_edit')) ? "href='apps_edit.php?id=".$row['uuid']."'" : null; + $tr_link = (permission_exists('app_edit')) ? "href='apps_edit.php?id=".escape($row['uuid'])."'" : null; */ echo "\n"; echo " "; /* if (permission_exists('app_edit')) { - echo " ".$row['name'].""; + echo " ".escape($row['name']).""; } else { */ @@ -112,17 +112,17 @@ } */ echo " \n"; - echo " ".$row['category']." \n"; - echo " ".$row['subcategory']." \n"; - echo " ".$row['version']." \n"; - echo " ".$row['$description']."\n"; + echo " ".escape($row['category'])." \n"; + echo " ".escape($row['subcategory'])." \n"; + echo " ".escape($row['version'])." \n"; + echo " ".escape($row['$description'])."\n"; /* // temporarily disabled echo " "; if (permission_exists('app_edit')) { - echo " $v_link_label_edit\n"; + echo " $v_link_label_edit\n"; } if (permission_exists('app_delete')) { - echo " $v_link_label_delete\n"; + echo " $v_link_label_delete\n"; } echo " \n"; */