瀏覽代碼

Fix XSS on login page by removing $_REQUEST[path]

markjcrane 4 年之前
父節點
當前提交
d94606b9d2
共有 1 個文件被更改,包括 0 次插入5 次删除
  1. 0 5
      resources/login.php

+ 0 - 5
resources/login.php

@@ -242,11 +242,6 @@
 //set variable if not set
 	if (!isset($_SESSION['login']['domain_name_visible']['boolean'])) { $_SESSION['login']['domain_name_visible']['boolean'] = null; }
 
-//set the requested destination after login
-	if (!empty($_REQUEST['path'])) {
-		$_SESSION['login']['destination']['url'] = $_REQUEST['path'];
-	}
-
 //set a default login destination
 	if (strlen($_SESSION['login']['destination']['url']) == 0) {
 		$_SESSION['login']['destination']['url'] = PROJECT_PATH."/core/user_settings/user_dashboard.php";