diff --git a/theme/rui/invoice-print.php b/theme/rui/invoice-print.php index 1fc5e66..ccd4c9c 100644 --- a/theme/rui/invoice-print.php +++ b/theme/rui/invoice-print.php @@ -105,7 +105,7 @@ if (isset($_GET["invoiceType"]) and !empty($_GET["invoiceType"])) { - $invoicePage = DIR_MODULE . "invoice/{$_GET['invoiceType']}.php"; + $invoicePage = DIR_MODULE . "invoice/". basename("{$_GET['page']}.php"); if (file_exists($invoicePage)) { require $invoicePage; diff --git a/theme/rui/print.php b/theme/rui/print.php index 2f5f0e1..713e7e8 100644 --- a/theme/rui/print.php +++ b/theme/rui/print.php @@ -99,7 +99,9 @@ } if(isset($_GET["page"]) and !empty($_GET["page"])) { - $printPage = DIR_MODULE . "print/{$_GET['page']}.php"; + + + $printPage = DIR_MODULE . "print/". basename("{$_GET['page']}.php"); if(file_exists($printPage)) { require $printPage;