diff --git a/app/emails/emails.php b/app/emails/emails.php
index a543197a23..c7e9e06d28 100644
--- a/app/emails/emails.php
+++ b/app/emails/emails.php
@@ -210,19 +210,19 @@ else {
$tr_link = "href='email_view.php?id=".$row['email_uuid']."'";
echo "
\n";
if ($_REQUEST['showall'] == true && permission_exists('emails_all')) {
- echo " | ".$row['domain_name']." | \n";
+ echo " ".escape($row['domain_name'])." | \n";
}
echo " ";
$sent_date = explode('.', $row['sent_date']);
echo $sent_date[0];
echo " | \n";
- echo " ".$text['label-type_'.$row['type']]." | \n";
- echo " ".$text['label-status_'.$row['status']]." | \n";
+ echo " ".$text['label-type_'.escape($row['type'])]." | \n";
+ echo " ".$text['label-status_'.escape($row['status'])]." | \n";
echo " ";
- echo " ".$text['label-message_view']." ";
+ echo " ".$text['label-message_view']." ";
if (permission_exists('email_download')) {
- echo " ".$text['label-download']." ";
+ echo " ".$text['label-download']." ";
}
if (permission_exists('email_resend')) {
echo " \n";
echo " | ";
- echo " ".$text['label-reference_cdr']."";
+ echo " ".$text['label-reference_cdr']."";
echo " ".($caller_id_name != '') ? " ".$caller_id_name." (".format_phone($caller_id_number).")" : $caller_id_number;
echo " ⇢ ".$destination_number;
echo " | \n";
echo " ";
- echo "$v_link_label_view";
+ echo "$v_link_label_view";
if (permission_exists('email_delete')) {
- echo "$v_link_label_delete";
+ echo "$v_link_label_delete";
}
echo " | \n";
echo "
\n";