Skip to content

Commit

Permalink
Fix low severity stored XSS in admin/pageEditMember.php and `admin/…
Browse files Browse the repository at this point in the history
…pageEditMemberPermissions.php`
  • Loading branch information
Ahmad Gneady committed Jul 3, 2021
1 parent 217a7b2 commit 6c3dbf5
Show file tree
Hide file tree
Showing 2 changed files with 2 additions and 2 deletions.
2 changes: 1 addition & 1 deletion app/admin/pageEditMember.php
Expand Up @@ -139,7 +139,7 @@
} elseif($_GET['groupID'] != '') {
// show the form for adding a new member, and pre-select the provided group
$groupID = intval($_GET['groupID']);
$group_name = sqlValue("select name from membership_groups where groupID='$groupID'");
$group_name = strip_tags(sqlValue("select name from membership_groups where groupID='$groupID'"));
if($group_name)
$addend = " to '{$group_name}'";
}
Expand Down
2 changes: 1 addition & 1 deletion app/admin/pageEditMemberPermissions.php
Expand Up @@ -19,7 +19,7 @@
$anonGroupID = sqlValue("select groupID from membership_groups where lcase(name)='" . strtolower(makeSafe($anonymousGroup)) . "'");
$adminGroupID = sqlValue("select groupID from membership_groups where name='Admins'");
$groupID = sqlValue("select groupID from membership_users where lcase(memberID)='{$memberID->sql}'");
$group = sqlValue("select name from membership_groups where groupID='{$groupID}'");
$group = strip_tags(sqlValue("select name from membership_groups where groupID='{$groupID}'"));
if($groupID == $anonGroupID || $memberID->raw == $anonymousMember || !$groupID || $groupID == $adminGroupID || $memberID->raw == $adminConfig['adminUsername']) {
// error in request. redirect to members page.
redirect('admin/pageViewMembers.php');
Expand Down

0 comments on commit 6c3dbf5

Please sign in to comment.