Skip to content

Commit 4d07349

Browse files
committed
Security: Sanitize English name input in sub_language_add.php to prevent dangerous characters
1 parent 4b01069 commit 4d07349

File tree

1 file changed

+1
-2
lines changed

1 file changed

+1
-2
lines changed

main/admin/sub_language_add.php

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -209,9 +209,8 @@ function allow_get_all_information_of_sub_language($parent_id, $sub_language_id)
209209

210210
if (isset($_POST['SubmitAddNewLanguage'])) {
211211
$original_name = $_POST['original_name'];
212-
$english_name = $_POST['english_name'];
213212
$isocode = $_POST['isocode'];
214-
$english_name = str_replace(' ', '_', $english_name);
213+
$english_name = api_replace_dangerous_char($_POST['english_name']);
215214
$isocode = str_replace(' ', '_', $isocode);
216215

217216
$sublanguage_available = $_POST['sub_language_is_visible'];

0 commit comments

Comments
 (0)