diff --git a/app/call_block/call_block.php b/app/call_block/call_block.php index 5b31876399..7d76bf0fa6 100644 --- a/app/call_block/call_block.php +++ b/app/call_block/call_block.php @@ -128,28 +128,28 @@ require_once "resources/require.php"; echo "\n"; echo " "; if (permission_exists('call_block_edit')) { - echo "".$row['call_block_number'].""; + echo "".escape($row['call_block_number']).""; } else { - echo $row['call_block_number']; + echo escape($row['call_block_number']); } echo " \n"; - echo " ".$row['call_block_name']."\n"; - echo " ".$row['call_block_count']."\n"; + echo " ".escape($row['call_block_name'])."\n"; + echo " ".escape($row['call_block_count'])."\n"; if (defined('TIME_24HR') && TIME_24HR == 1) { $tmp_date_added = date("j M Y H:i:s", $row['date_added']); } else { $tmp_date_added = date("j M Y h:i:sa", $row['date_added']); } echo " ".$tmp_date_added."\n"; - echo " ".$row['call_block_action']."\n"; - echo " ".$text['label-'.$row['call_block_enabled']]."\n"; + echo " ".escape($row['call_block_action'])."\n"; + echo " ".$text['label-'.escape($row['call_block_enabled'])]."\n"; echo " "; if (permission_exists('call_block_edit')) { - echo "$v_link_label_edit"; + echo "$v_link_label_edit"; } if (permission_exists('call_block_delete')) { - echo "$v_link_label_delete"; + echo "$v_link_label_delete"; }; echo " "; echo "\n";