Skip to content

Commit 2edde58

Browse files
committed
Add htmlentities to prevent xss
1 parent 9e37a51 commit 2edde58

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

web/templates/pages/list_key.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -42,7 +42,7 @@
4242
<a id="delete_link_<?=$i?>" class="data-controls do_delete" title="<?=_('delete');?>">
4343
<i class="fas fa-trash status-icon red status-icon dim do_delete"></i>
4444
<?php if (($_SESSION['userContext'] === 'admin') && (isset($_GET['user'])) && ($_GET['user'] !== 'admin')) { ?>
45-
<input type="hidden" name="delete_url" value="/delete/key/?user=<?=$_GET['user']?>&key=<?=$key?>&token=<?=$_SESSION['token']?>" />
45+
<input type="hidden" name="delete_url" value="/delete/key/?user=<?=htmlentities($_GET['user']);?>&key=<?=$key?>&token=<?=$_SESSION['token']?>" />
4646
<?php } else { ?>
4747
<input type="hidden" name="delete_url" value="/delete/key/?key=<?=$key?>&token=<?=$_SESSION['token']?>" />
4848
<?php } ?>

0 commit comments

Comments
 (0)