From 937ed5a1d05f1d38cb50b1af7591b2c56d2a2cf6 Mon Sep 17 00:00:00 2001 From: Yannick Warnier Date: Fri, 16 Oct 2015 02:47:03 -0500 Subject: [PATCH] Add remove_XSS() to folder creation process --- main/inc/ajax/document.ajax.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/main/inc/ajax/document.ajax.php b/main/inc/ajax/document.ajax.php index 8aee089bc2..609a1fa607 100755 --- a/main/inc/ajax/document.ajax.php +++ b/main/inc/ajax/document.ajax.php @@ -76,7 +76,7 @@ switch ($action) { case 'document_destination': //obtained the bootstrap-select selected value via ajax $dirValue = isset($_POST['dirValue']) ? $_POST['dirValue'] : null; - echo $dirValue; + echo Security::remove_XSS($dirValue); break; } exit;