Skip to content

Commit 3740eec

Browse files
committed
Security: Add filter on GET data in admin users list - refs BT#21427
1 parent 29357ac commit 3740eec

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

main/admin/user_list.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -246,7 +246,7 @@ function prepare_user_sql_query($getCount)
246246
foreach ($keywordList as $keyword) {
247247
$keywordListValues[$keyword] = null;
248248
if (isset($_GET[$keyword]) && !empty($_GET[$keyword])) {
249-
$keywordListValues[$keyword] = $_GET[$keyword];
249+
$keywordListValues[$keyword] = Security::remove_XSS($_GET[$keyword]);
250250
$atLeastOne = true;
251251
}
252252
}

0 commit comments

Comments
 (0)