diff --git a/app/devices/device_vendors.php b/app/devices/device_vendors.php index 889f232180..a6efcdbdcb 100644 --- a/app/devices/device_vendors.php +++ b/app/devices/device_vendors.php @@ -108,7 +108,7 @@ echo " "; } echo " "; - echo " \n"; + echo " \n"; echo " \n"; echo " \n"; echo " \n"; @@ -138,18 +138,18 @@ if (is_array($result)) { foreach($result as $row) { if (permission_exists('device_vendor_edit')) { - $tr_link = "href='device_vendor_edit.php?id=".$row['device_vendor_uuid']."'"; + $tr_link = "href='device_vendor_edit.php?id=".escape($row['device_vendor_uuid'])."'"; } echo "\n"; - echo " ".$row['name']." \n"; - echo " ".$row['enabled']." \n"; - echo " ".$row['description']." \n"; + echo " ".escape($row['name'])." \n"; + echo " ".escape($row['enabled'])." \n"; + echo " ".escape($row['description'])." \n"; echo " "; if (permission_exists('device_vendor_edit')) { - echo "$v_link_label_edit"; + echo "$v_link_label_edit"; } if (permission_exists('device_vendor_delete')) { - echo "$v_link_label_delete"; + echo "$v_link_label_delete"; } echo " \n"; echo "\n";