Escape message_media_source to prevent xss.

This commit is contained in:
FusionPBX
2021-06-04 10:28:31 -06:00
committed by GitHub
parent 123407f3b8
commit 3073001e5c

View File

@@ -34,7 +34,7 @@
//get media uuid
$message_media_uuid = $_GET['id'];
$message_media_source = $_GET['src'];
$message_media_source = escape($_GET['src']);
$action = $_GET['action'];
//get media
@@ -96,4 +96,4 @@
}
?>
?>