diff --git a/core/default_settings/default_setting_edit.php b/core/default_settings/default_setting_edit.php
index 584f306a33..8c67168eb0 100644
--- a/core/default_settings/default_setting_edit.php
+++ b/core/default_settings/default_setting_edit.php
@@ -464,7 +464,7 @@ if (count($_POST) > 0 && strlen($_POST["persistformvar"]) == 0) {
echo " \n";
}
else {
- echo " \n";
+ echo " \n";
}
echo "
\n";
echo $text['description-value']."\n";
@@ -553,4 +553,4 @@ if (count($_POST) > 0 && strlen($_POST["persistformvar"]) == 0) {
//include the footer
require_once "resources/footer.php";
-?>
\ No newline at end of file
+?>
diff --git a/core/default_settings/default_settings.php b/core/default_settings/default_settings.php
index 09690a6b2d..b625429f34 100644
--- a/core/default_settings/default_settings.php
+++ b/core/default_settings/default_settings.php
@@ -422,7 +422,7 @@ if (permission_exists("domain_select") && permission_exists("domain_setting_add"
elseif ($category == "provision" && $subcategory == "password" && $name == "var" ) {
echo " ******** \n";
} else {
- echo " ".substr($row['default_setting_value'],0,58);
+ echo " ".htmlspecialchars(substr($row['default_setting_value'],0,58));
}
echo " \n";
echo " \n";
@@ -491,4 +491,4 @@ if (permission_exists("domain_select") && permission_exists("domain_setting_add"
//include the footer
require_once "resources/footer.php";
-?>
\ No newline at end of file
+?>
diff --git a/themes/enhanced/template.php b/themes/enhanced/template.php
index 935b18c58b..d2849235f0 100644
--- a/themes/enhanced/template.php
+++ b/themes/enhanced/template.php
@@ -1605,6 +1605,9 @@ if (strlen($_SESSION['message']) > 0) {
fusionpbx.com. All rights reserved.\n";
echo "