diff --git a/app/call_block/call_block.php b/app/call_block/call_block.php
index 5b31876399..7d76bf0fa6 100644
--- a/app/call_block/call_block.php
+++ b/app/call_block/call_block.php
@@ -128,28 +128,28 @@ require_once "resources/require.php";
echo "
\n";
echo " | ";
if (permission_exists('call_block_edit')) {
- echo "".$row['call_block_number']."";
+ echo "".escape($row['call_block_number'])."";
}
else {
- echo $row['call_block_number'];
+ echo escape($row['call_block_number']);
}
echo " | \n";
- echo " ".$row['call_block_name']." | \n";
- echo " ".$row['call_block_count']." | \n";
+ echo " ".escape($row['call_block_name'])." | \n";
+ echo " ".escape($row['call_block_count'])." | \n";
if (defined('TIME_24HR') && TIME_24HR == 1) {
$tmp_date_added = date("j M Y H:i:s", $row['date_added']);
} else {
$tmp_date_added = date("j M Y h:i:sa", $row['date_added']);
}
echo " ".$tmp_date_added." | \n";
- echo " ".$row['call_block_action']." | \n";
- echo " ".$text['label-'.$row['call_block_enabled']]." | \n";
+ echo " ".escape($row['call_block_action'])." | \n";
+ echo " ".$text['label-'.escape($row['call_block_enabled'])]." | \n";
echo " ";
if (permission_exists('call_block_edit')) {
- echo "$v_link_label_edit";
+ echo "$v_link_label_edit";
}
if (permission_exists('call_block_delete')) {
- echo "$v_link_label_delete";
+ echo "$v_link_label_delete";
};
echo " | ";
echo "
\n";