diff --git a/app/conferences/conferences.php b/app/conferences/conferences.php
index cf3ebd4a9e..4c2ac50301 100644
--- a/app/conferences/conferences.php
+++ b/app/conferences/conferences.php
@@ -144,18 +144,18 @@ else {
$conference_name = str_replace("-", " ", $conference_name);
$tr_link = "href='conference_edit.php?id=".$row['conference_uuid']."'";
echo "
\n";
- echo " | ".$conference_name." | \n";
- echo " ".$row['conference_extension']." | \n";
- echo " ".$row['conference_profile']." | \n";
- echo " ".$row['conference_order']." | \n";
- echo " ".$text['label-'.$row['conference_enabled']]." | \n";
- echo " ".$row['conference_description']." | \n";
+ echo " ".$conference_name." | \n";
+ echo " ".escape($row['conference_extension'])." | \n";
+ echo " ".escape($row['conference_profile'])." | \n";
+ echo " ".escape($row['conference_order'])." | \n";
+ echo " ".$text['label-'.escape($row['conference_enabled'])]." | \n";
+ echo " ".escape($row['conference_description'])." | \n";
echo " ";
if (permission_exists('conference_edit')) {
- echo "$v_link_label_edit";
+ echo "$v_link_label_edit";
}
if (permission_exists('conference_delete')) {
- echo "$v_link_label_delete";
+ echo "$v_link_label_delete";
}
echo " | \n";
echo "
\n";