mirror of
				https://github.com/Mibew/mibew.git
				synced 2025-10-25 07:46:57 +03:00 
			
		
		
		
	Fix XSS in error message (thanks to Sharif aka Vincent Pentester)
This commit is contained in:
		
							parent
							
								
									1c3d9c98b4
								
							
						
					
					
						commit
						b8bad36510
					
				| @ -51,7 +51,7 @@ class ButtonCodeController extends AbstractController | ||||
|         $image_locales_map = $this->getImageLocalesMap(MIBEW_FS_ROOT . '/locales'); | ||||
|         $image = $request->query->get('i', 'mibew'); | ||||
|         if (!isset($image_locales_map[$image])) { | ||||
|             $page['errors'][] = 'Unknown image: ' . $image; | ||||
|             $page['errors'][] = 'Unknown image: ' . htmlspecialchars($image); | ||||
|             $avail = array_keys($image_locales_map); | ||||
|             $image = $avail[0]; | ||||
|         } | ||||
|  | ||||
		Loading…
	
		Reference in New Issue
	
	Block a user