We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 9e37a51 commit 2edde58Copy full SHA for 2edde58
1 file changed
web/templates/pages/list_key.html
@@ -42,7 +42,7 @@
42
<a id="delete_link_<?=$i?>" class="data-controls do_delete" title="<?=_('delete');?>">
43
<i class="fas fa-trash status-icon red status-icon dim do_delete"></i>
44
<?php if (($_SESSION['userContext'] === 'admin') && (isset($_GET['user'])) && ($_GET['user'] !== 'admin')) { ?>
45
- <input type="hidden" name="delete_url" value="/delete/key/?user=<?=$_GET['user']?>&key=<?=$key?>&token=<?=$_SESSION['token']?>" />
+ <input type="hidden" name="delete_url" value="/delete/key/?user=<?=htmlentities($_GET['user']);?>&key=<?=$key?>&token=<?=$_SESSION['token']?>" />
46
<?php } else { ?>
47
<input type="hidden" name="delete_url" value="/delete/key/?key=<?=$key?>&token=<?=$_SESSION['token']?>" />
48
<?php } ?>
0 commit comments