Эх сурвалжийг харах

[security] import pages xss prevention (#6553)

agree 2 жил өмнө
parent
commit
f961618dae

+ 1 - 1
core/users/user_imports.php

@@ -167,7 +167,7 @@
 			//loop through user columns
 			$x = 0;
 			foreach ($line_fields as $line_field) {
-				$line_field = trim(trim($line_field), $enclosure);
+				$line_field = trim(escape(trim($line_field)), $enclosure);
 				echo "<tr>\n";
 				echo "	<td width='30%' class='vncell' valign='top' align='left' nowrap='nowrap'>\n";
 				//echo "    ".$text['label-zzz']."\n";