mirror of
https://github.com/fusionpbx/fusionpbx.git
synced 2026-01-26 02:29:15 +00:00
Escape message_media_source to prevent xss.
This commit is contained in:
@@ -34,7 +34,7 @@
|
||||
|
||||
//get media uuid
|
||||
$message_media_uuid = $_GET['id'];
|
||||
$message_media_source = $_GET['src'];
|
||||
$message_media_source = escape($_GET['src']);
|
||||
$action = $_GET['action'];
|
||||
|
||||
//get media
|
||||
@@ -96,4 +96,4 @@
|
||||
|
||||
}
|
||||
|
||||
?>
|
||||
?>
|
||||
|
||||
Reference in New Issue
Block a user