diff --git a/core/users/user_edit.php b/core/users/user_edit.php
index 9a02117025..b441f012d0 100644
--- a/core/users/user_edit.php
+++ b/core/users/user_edit.php
@@ -584,11 +584,11 @@ if (count($_POST) > 0 && $_POST["persistform"] != "1") {
echo "
".$text['label-username']." | ";
echo " ";
if (permission_exists("user_edit")) {
- echo " \n";
+ echo " \n";
}
else {
- echo " ".$username."\n";
- echo " \n";
+ echo " ".escape($username)."\n";
+ echo " \n";
}
echo " | ";
echo " ";
@@ -626,7 +626,7 @@ if (count($_POST) > 0 && $_POST["persistform"] != "1") {
unset($prep_statement, $result, $row);
foreach ($_SESSION['app']['languages'] as $code) {
$selected = ($code == $user_settings['domain']['language']['code']) ? "selected='selected'" : null;
- echo " \n";
+ echo " \n";
}
echo " \n";
echo "
\n";
@@ -655,10 +655,10 @@ if (count($_POST) > 0 && $_POST["persistform"] != "1") {
echo "