mirror of
https://github.com/pandorafms/pandorafms.git
synced 2025-07-29 00:34:46 +02:00
Merge branch 'ent-10160-stored-cross-site-scripting-vulnerability-in-visual-console-module' into 'develop'
Ent 10160 stored cross site scripting vulnerability in visual console module See merge request artica/pandorafms!5447
This commit is contained in:
commit
7c379062cf
@ -177,7 +177,7 @@ switch ($activeTab) {
|
||||
$background_color = (string) get_parameter('background_color');
|
||||
$width = (int) get_parameter('width');
|
||||
$height = (int) get_parameter('height');
|
||||
$visualConsoleName = (string) get_parameter('name');
|
||||
$visualConsoleName = io_safe_input((string) get_parameter('name'));
|
||||
$is_favourite = (int) get_parameter('is_favourite_sent');
|
||||
$auto_adjust = (int) get_parameter('auto_adjust_sent');
|
||||
|
||||
|
@ -357,7 +357,7 @@ final class Container extends Model
|
||||
$config['dbpass'].$row['id'].$config['id_user']
|
||||
);
|
||||
|
||||
return \io_safe_output($row);
|
||||
return $row;
|
||||
}
|
||||
|
||||
|
||||
|
Loading…
x
Reference in New Issue
Block a user