Security: Add filter on GET data in admin users list - refs BT#21427

pull/5182/head
Yannick Warnier 2 years ago
parent 29357ac548
commit 3740eece4c
  1. 2
      main/admin/user_list.php

@ -246,7 +246,7 @@ function prepare_user_sql_query($getCount)
foreach ($keywordList as $keyword) {
$keywordListValues[$keyword] = null;
if (isset($_GET[$keyword]) && !empty($_GET[$keyword])) {
$keywordListValues[$keyword] = $_GET[$keyword];
$keywordListValues[$keyword] = Security::remove_XSS($_GET[$keyword]);
$atLeastOne = true;
}
}

Loading…
Cancel
Save