mirror of
https://github.com/Mibew/mibew.git
synced 2025-01-31 05:20:30 +03:00
Fix XSS in error message (thanks to Sharif aka Vincent Pentester)
This commit is contained in:
parent
1c3d9c98b4
commit
b8bad36510
@ -51,7 +51,7 @@ class ButtonCodeController extends AbstractController
|
|||||||
$image_locales_map = $this->getImageLocalesMap(MIBEW_FS_ROOT . '/locales');
|
$image_locales_map = $this->getImageLocalesMap(MIBEW_FS_ROOT . '/locales');
|
||||||
$image = $request->query->get('i', 'mibew');
|
$image = $request->query->get('i', 'mibew');
|
||||||
if (!isset($image_locales_map[$image])) {
|
if (!isset($image_locales_map[$image])) {
|
||||||
$page['errors'][] = 'Unknown image: ' . $image;
|
$page['errors'][] = 'Unknown image: ' . htmlspecialchars($image);
|
||||||
$avail = array_keys($image_locales_map);
|
$avail = array_keys($image_locales_map);
|
||||||
$image = $avail[0];
|
$image = $avail[0];
|
||||||
}
|
}
|
||||||
|
Loading…
Reference in New Issue
Block a user