Skip to content

Commit

Permalink
File name not properly checked against XSS #1116
Browse files Browse the repository at this point in the history
  • Loading branch information
Fasse committed Oct 18, 2021
1 parent 4f15393 commit 6b3820a
Showing 1 changed file with 2 additions and 1 deletion.
3 changes: 2 additions & 1 deletion adm_program/system/bootstrap/function.php
Expand Up @@ -392,6 +392,7 @@ function admFuncVariableIsValid(array $array, $variableName, $datatype, array $o
{
if ($value !== '')
{
$value = StringUtils::strStripTags(urldecode($value));
StringUtils::strIsValidFileName($value, false);
}
}
Expand Down Expand Up @@ -454,7 +455,7 @@ function admFuncVariableIsValid(array $array, $variableName, $datatype, array $o
break;

case 'string':
$value = StringUtils::strStripTags(SecurityUtils::encodeHTML($value));
$value = SecurityUtils::encodeHTML(StringUtils::strStripTags($value));
break;

case 'html':
Expand Down

0 comments on commit 6b3820a

Please sign in to comment.