diff --git a/functions.php b/functions.php index 4d1b8c44..d42d0c07 100644 --- a/functions.php +++ b/functions.php @@ -1016,7 +1016,7 @@ function addToMailQueue($mysqli, $data) $recipient_name = strval($email['recipient_name']); $subject = strval($email['subject']); $body = strval($email['body']); - $cal_str = strval($email['cal_str']); + $cal_str = mysqli_escape_string($mysqli,$email['cal_str']); // Check if 'email_queued_at' is set and not empty if (isset($email['queued_at']) && !empty($email['queued_at'])) { diff --git a/post/ticket.php b/post/ticket.php index af0ceab6..df111860 100644 --- a/post/ticket.php +++ b/post/ticket.php @@ -1513,7 +1513,8 @@ if (isset($_POST['edit_ticket_schedule'])) { $user_name = sanitizeInput($row['user_name']); $user_email = sanitizeInput($row['user_email']); $cal_subject = $ticket_number . ": " . $client_name . " - " . $ticket_subject; - $cal_description = $ticket_details . " - " . $full_ticket_url; + $ticket_details_truncated = substr($ticket_details, 0, 100); + $cal_description = $ticket_details_truncated . " - " . $full_ticket_url; $cal_location = sanitizeInput($row["location_address"]); $email_datetime = date('l, F j, Y \a\t g:ia', strtotime($schedule));