mirror of
https://github.com/Mibew/mibew.git
synced 2025-01-31 05:20:30 +03:00
Fix XSS in error message (thanks to Sharif aka Vincent Pentester)
This commit is contained in:
parent
1c3d9c98b4
commit
b8bad36510
@ -51,7 +51,7 @@ class ButtonCodeController extends AbstractController
|
||||
$image_locales_map = $this->getImageLocalesMap(MIBEW_FS_ROOT . '/locales');
|
||||
$image = $request->query->get('i', 'mibew');
|
||||
if (!isset($image_locales_map[$image])) {
|
||||
$page['errors'][] = 'Unknown image: ' . $image;
|
||||
$page['errors'][] = 'Unknown image: ' . htmlspecialchars($image);
|
||||
$avail = array_keys($image_locales_map);
|
||||
$image = $avail[0];
|
||||
}
|
||||
|
Loading…
Reference in New Issue
Block a user