diff --git a/core/groups/group_permissions.php b/core/groups/group_permissions.php index 077b09a611..0ee2216dbf 100644 --- a/core/groups/group_permissions.php +++ b/core/groups/group_permissions.php @@ -328,7 +328,7 @@ echo " if (new_group_name != null) {\n"; echo " new_group_desc = prompt('".$text['message-new_group_description']."');\n"; echo " if (new_group_desc != null) {\n"; - echo " window.location = 'permissions_copy.php?group_name=".$group_name."&new_group_name=' + new_group_name + '&new_group_desc=' + new_group_desc;\n"; + echo " window.location = 'permissions_copy.php?group_name=".escape($group_name)."&new_group_name=' + new_group_name + '&new_group_desc=' + new_group_desc;\n"; echo " }\n"; echo " }\n"; echo " }\n"; @@ -352,11 +352,11 @@ //show the content echo "
\n"; - echo "\n"; + echo "\n"; echo "\n"; echo " \n"; echo " \n"; echo " \n"; - echo " \n"; - echo " \n"; - echo " \n"; + echo " \n"; + echo " \n"; + echo " \n"; echo "\n"; $c = ($c == 0) ? 1 : 0; @@ -487,4 +487,4 @@ //show the footer require_once "resources/footer.php"; -?> \ No newline at end of file +?>
"; - echo " ".$text['header-group_permissions'].$group_name.""; + echo " ".$text['header-group_permissions'].escape($group_name).""; echo "

"; echo "
\n"; @@ -404,9 +404,9 @@ foreach ($app['permissions'] as $permission_index => $row) { $checked = ($permissions_db_checklist[$row['name']] == "true") ? "checked='checked'" : null; echo "
".$row['name']."".$row['description']." ".escape($row['name'])."".escape($row['description'])."