diff --git a/app/emails/emails.php b/app/emails/emails.php index a543197a23..c7e9e06d28 100644 --- a/app/emails/emails.php +++ b/app/emails/emails.php @@ -210,19 +210,19 @@ else { $tr_link = "href='email_view.php?id=".$row['email_uuid']."'"; echo "\n"; if ($_REQUEST['showall'] == true && permission_exists('emails_all')) { - echo " ".$row['domain_name']."\n"; + echo " ".escape($row['domain_name'])."\n"; } echo " "; $sent_date = explode('.', $row['sent_date']); echo $sent_date[0]; echo " \n"; - echo " ".$text['label-type_'.$row['type']]."\n"; - echo " ".$text['label-status_'.$row['status']]."\n"; + echo " ".$text['label-type_'.escape($row['type'])]."\n"; + echo " ".$text['label-status_'.escape($row['status'])]."\n"; echo " "; - echo " ".$text['label-message_view']."  "; + echo " ".$text['label-message_view']."  "; if (permission_exists('email_download')) { - echo " ".$text['label-download']."  "; + echo " ".$text['label-download']."  "; } if (permission_exists('email_resend')) { echo " \n"; echo " "; - echo " ".$text['label-reference_cdr'].""; + echo " ".$text['label-reference_cdr'].""; echo " ".($caller_id_name != '') ? "  ".$caller_id_name." (".format_phone($caller_id_number).")" : $caller_id_number; echo "    ".$destination_number; echo " \n"; echo " "; - echo "$v_link_label_view"; + echo "$v_link_label_view"; if (permission_exists('email_delete')) { - echo "$v_link_label_delete"; + echo "$v_link_label_delete"; } echo " \n"; echo "\n";