From 78d4bff3020efefdf35e18d5605008524e3e09a2 Mon Sep 17 00:00:00 2001 From: AlexanderDCrane <40072887+AlexanderDCrane@users.noreply.github.com> Date: Mon, 27 Aug 2018 20:28:54 -0600 Subject: [PATCH] Update apps.php (#3314) --- core/apps/apps.php | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/core/apps/apps.php b/core/apps/apps.php index 5eeeefa429..8deb5170cc 100644 --- a/core/apps/apps.php +++ b/core/apps/apps.php @@ -97,13 +97,13 @@ $row['$description'] = $description; /* - $tr_link = (permission_exists('app_edit')) ? "href='apps_edit.php?id=".$row['uuid']."'" : null; + $tr_link = (permission_exists('app_edit')) ? "href='apps_edit.php?id=".escape($row['uuid'])."'" : null; */ echo "\n"; echo " "; /* if (permission_exists('app_edit')) { - echo " ".$row['name'].""; + echo " ".escape($row['name']).""; } else { */ @@ -112,17 +112,17 @@ } */ echo " \n"; - echo " ".$row['category']." \n"; - echo " ".$row['subcategory']." \n"; - echo " ".$row['version']." \n"; - echo " ".$row['$description']."\n"; + echo " ".escape($row['category'])." \n"; + echo " ".escape($row['subcategory'])." \n"; + echo " ".escape($row['version'])." \n"; + echo " ".escape($row['$description'])."\n"; /* // temporarily disabled echo " "; if (permission_exists('app_edit')) { - echo " $v_link_label_edit\n"; + echo " $v_link_label_edit\n"; } if (permission_exists('app_delete')) { - echo " $v_link_label_delete\n"; + echo " $v_link_label_delete\n"; } echo " \n"; */