From 3d60e608420576a54b57a5f8c9ae9ee457b5066c Mon Sep 17 00:00:00 2001 From: Johannes Meyer Date: Thu, 3 Dec 2015 15:17:09 +0100 Subject: [PATCH] SortBox: Fix too strict sort param check One was able to produce invalid SQL or other errors by adding "sort=" as parameter. --- library/Icinga/Web/Widget/SortBox.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/library/Icinga/Web/Widget/SortBox.php b/library/Icinga/Web/Widget/SortBox.php index 5e7b35915..45ceebc44 100644 --- a/library/Icinga/Web/Widget/SortBox.php +++ b/library/Icinga/Web/Widget/SortBox.php @@ -118,7 +118,7 @@ class SortBox extends AbstractWidget if ($request === null) { $request = Icinga::app()->getRequest(); } - if (null === $sort = $request->getParam('sort')) { + if (! ($sort = $request->getParam('sort'))) { list($sort, $dir) = $this->getSortDefaults(); } else { list($_, $dir) = $this->getSortDefaults($sort);