浏览代码

[security] import pages xss prevention (#6553)

agree 2 年之前
父节点
当前提交
f961618dae
共有 1 个文件被更改,包括 1 次插入1 次删除
  1. 1 1
      core/users/user_imports.php

+ 1 - 1
core/users/user_imports.php

@@ -167,7 +167,7 @@
 			//loop through user columns
 			$x = 0;
 			foreach ($line_fields as $line_field) {
-				$line_field = trim(trim($line_field), $enclosure);
+				$line_field = trim(escape(trim($line_field)), $enclosure);
 				echo "<tr>\n";
 				echo "	<td width='30%' class='vncell' valign='top' align='left' nowrap='nowrap'>\n";
 				//echo "    ".$text['label-zzz']."\n";