diff --git a/app/conferences/conferences.php b/app/conferences/conferences.php index cf3ebd4a9e..4c2ac50301 100644 --- a/app/conferences/conferences.php +++ b/app/conferences/conferences.php @@ -144,18 +144,18 @@ else { $conference_name = str_replace("-", " ", $conference_name); $tr_link = "href='conference_edit.php?id=".$row['conference_uuid']."'"; echo "\n"; - echo " ".$conference_name." \n"; - echo " ".$row['conference_extension']." \n"; - echo " ".$row['conference_profile']." \n"; - echo " ".$row['conference_order']." \n"; - echo " ".$text['label-'.$row['conference_enabled']]." \n"; - echo " ".$row['conference_description']." \n"; + echo " ".$conference_name." \n"; + echo " ".escape($row['conference_extension'])." \n"; + echo " ".escape($row['conference_profile'])." \n"; + echo " ".escape($row['conference_order'])." \n"; + echo " ".$text['label-'.escape($row['conference_enabled'])]." \n"; + echo " ".escape($row['conference_description'])." \n"; echo " "; if (permission_exists('conference_edit')) { - echo "$v_link_label_edit"; + echo "$v_link_label_edit"; } if (permission_exists('conference_delete')) { - echo "$v_link_label_delete"; + echo "$v_link_label_delete"; } echo "\n"; echo "\n";