diff --git a/ticket_reply_edit_modal.php b/ticket_reply_edit_modal.php
index bf4c7e6d..65254056 100644
--- a/ticket_reply_edit_modal.php
+++ b/ticket_reply_edit_modal.php
@@ -2,7 +2,7 @@
-
Time worked
+
@@ -28,8 +29,8 @@
diff --git a/tickets.php b/tickets.php
index 53978234..2a80c621 100644
--- a/tickets.php
+++ b/tickets.php
@@ -12,13 +12,13 @@ if (isset($_GET['p'])) {
}
if (isset($_GET['q'])) {
- $q = strip_tags(mysqli_real_escape_string($mysqli, $_GET['q']));
+ $q = sanitizeInput($_GET['q']);
} else {
$q = "";
}
if (!empty($_GET['sb'])) {
- $sb = strip_tags(mysqli_real_escape_string($mysqli, $_GET['sb']));
+ $sb = sanitizeInput($_GET['sb']);
} else {
$sb = "ticket_number";
}
@@ -59,8 +59,7 @@ if (isset($_GET['assigned']) & !empty($_GET['assigned'])) {
} else {
$ticket_assigned_filter = intval($_GET['assigned']);
}
-}
-else{
+} else {
// Default - any
$ticket_assigned_filter = '';
}
@@ -74,8 +73,8 @@ if (empty($_GET['canned_date'])) {
}
if ($_GET['canned_date'] == "custom" && !empty($_GET['dtf'])) {
- $dtf = strip_tags(mysqli_real_escape_string($mysqli, $_GET['dtf']));
- $dtt = strip_tags(mysqli_real_escape_string($mysqli, $_GET['dtt']));
+ $dtf = sanitizeInput($_GET['dtf']);
+ $dtt = sanitizeInput($_GET['dtt']);
} elseif ($_GET['canned_date'] == "today") {
$dtf = date('Y-m-d');
$dtt = date('Y-m-d');
@@ -132,22 +131,22 @@ $num_rows = mysqli_fetch_row(mysqli_query($mysqli, "SELECT FOUND_ROWS()"));
//Get Total tickets open
$sql_total_tickets_open = mysqli_query($mysqli, "SELECT COUNT(ticket_id) AS total_tickets_open FROM tickets WHERE ticket_status != 'Closed' AND company_id = $session_company_id");
$row = mysqli_fetch_array($sql_total_tickets_open);
-$total_tickets_open = $row['total_tickets_open'];
+$total_tickets_open = intval($row['total_tickets_open']);
//Get Total tickets closed
$sql_total_tickets_closed = mysqli_query($mysqli, "SELECT COUNT(ticket_id) AS total_tickets_closed FROM tickets WHERE ticket_status = 'Closed' AND company_id = $session_company_id");
$row = mysqli_fetch_array($sql_total_tickets_closed);
-$total_tickets_closed = $row['total_tickets_closed'];
+$total_tickets_closed = intval($row['total_tickets_closed']);
//Get Unassigned tickets
$sql_total_tickets_unassigned = mysqli_query($mysqli, "SELECT COUNT(ticket_id) AS total_tickets_unassigned FROM tickets WHERE ticket_assigned_to = '0' AND ticket_status != 'Closed' AND company_id = $session_company_id");
$row = mysqli_fetch_array($sql_total_tickets_unassigned);
-$total_tickets_unassigned = $row['total_tickets_unassigned'];
+$total_tickets_unassigned = intval($row['total_tickets_unassigned']);
//Get Total tickets assigned to me
$sql_total_tickets_assigned = mysqli_query($mysqli, "SELECT COUNT(ticket_id) AS total_tickets_assigned FROM tickets WHERE ticket_assigned_to = $session_user_id AND ticket_status != 'Closed' AND company_id = $session_company_id");
$row = mysqli_fetch_array($sql_total_tickets_assigned);
-$user_active_assigned_tickets = $row['total_tickets_assigned'];
+$user_active_assigned_tickets = intval($row['total_tickets_assigned']);
?>