From eedd6407b5d8d7698529f178e1bcd9c70ddc7197 Mon Sep 17 00:00:00 2001 From: enriquecd Date: Thu, 16 Nov 2017 12:11:07 +0100 Subject: [PATCH] Apply Safe input to ui_get_url_refresh function return - #1574 --- pandora_console/include/functions_ui.php | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pandora_console/include/functions_ui.php b/pandora_console/include/functions_ui.php index e76ba9399f..22af9f9df4 100755 --- a/pandora_console/include/functions_ui.php +++ b/pandora_console/include/functions_ui.php @@ -2300,6 +2300,8 @@ function ui_get_url_refresh ($params = false, $relative = true, $add_post = true } $url = htmlspecialchars ($url); + + $url = io_safe_input($url); if (! $relative) { return ui_get_full_url ($url);