From a7cfef2aea3369e973cac20db81fefa3e5d79ae9 Mon Sep 17 00:00:00 2001 From: AlexanderDCrane <40072887+AlexanderDCrane@users.noreply.github.com> Date: Fri, 31 Aug 2018 14:36:03 -0600 Subject: [PATCH] Update conference_control_details.php (#3398) --- .../conference_control_details.php | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/app/conference_controls/conference_control_details.php b/app/conference_controls/conference_control_details.php index 53dbfc2fde..20c2055f23 100644 --- a/app/conference_controls/conference_control_details.php +++ b/app/conference_controls/conference_control_details.php @@ -86,7 +86,7 @@ echo " ".$text['title-conference_control_details']."\n"; //echo "
\n"; //echo " \n"; - //echo " \n"; + //echo " \n"; //echo " \n"; //echo " \n"; //echo "
\n"; @@ -112,19 +112,19 @@ if (is_array($result)) { foreach($result as $row) { if (permission_exists('conference_control_detail_edit')) { - $tr_link = "href='conference_control_detail_edit.php?conference_control_uuid=".$row['conference_control_uuid']."&id=".$row['conference_control_detail_uuid']."'"; + $tr_link = "href='conference_control_detail_edit.php?conference_control_uuid=".escape($row['conference_control_uuid'])."&id=".escape($row['conference_control_detail_uuid'])."'"; } echo "\n"; - echo " ".$row['control_digits']." \n"; - echo " ".$row['control_action']." \n"; - echo " ".$row['control_data']." \n"; - echo " ".$row['control_enabled']." \n"; + echo " ".escape($row['control_digits'])." \n"; + echo " ".escape($row['control_action'])." \n"; + echo " ".escape($row['control_data'])." \n"; + echo " ".escape($row['control_enabled'])." \n"; echo " "; if (permission_exists('conference_control_detail_edit')) { - echo "$v_link_label_edit"; + echo "$v_link_label_edit"; } if (permission_exists('conference_control_detail_delete')) { - echo "$v_link_label_delete"; + echo "$v_link_label_delete"; } echo " \n"; echo "\n";