Skip to content

Commit a162fe0

Browse files
Merge pull request hestiacp#720 from Flatta/secfix-xss-pwreset
Fix XSS in Password Reset
2 parents 3e579ee + 558643d commit a162fe0

File tree

2 files changed

+3
-3
lines changed

2 files changed

+3
-3
lines changed

web/templates/reset_2.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@
2121
<tr>
2222
<td>
2323
<input type="hidden" name="action" value="confirm">
24-
<input type="hidden" name="user" value="<?php echo $_GET['user'];?>">
24+
<input type="hidden" name="user" value="<?=htmlentities($_GET['user'], ENT_QUOTES|ENT_HTML5)?>">
2525
<input tabindex="1" type="text" size="20px" style="width:240px" name="code" class="vst-input">
2626
</td>
2727
</tr>

web/templates/reset_3.html

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -13,8 +13,8 @@
1313
<tr>
1414
<td style="padding: 12px 0 0 2px;">
1515
<input type="hidden" name="action" value="confirm" >
16-
<input type="hidden" name="user" value="<?php echo $_GET['user'];?>" >
17-
<input type="hidden" name="code" value="<?php echo $_GET['code'];?>" >
16+
<input type="hidden" name="user" value="<?=htmlentities($_GET['user'], ENT_QUOTES|ENT_HTML5)?>" >
17+
<input type="hidden" name="code" value="<?=htmlentities($_GET['code'], ENT_QUOTES|ENT_HTML5)?>" >
1818
<?php print __('New Password');?>
1919
</td>
2020
</tr>

0 commit comments

Comments
 (0)