From 9cf8da5a4a3303a9d90f1089864e39a84287359b Mon Sep 17 00:00:00 2001 From: fusionate Date: Thu, 20 Mar 2025 09:53:17 -0600 Subject: [PATCH] Access Control - Edit: Escape submitted values in dig command. --- app/access_controls/access_control_edit.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/access_controls/access_control_edit.php b/app/access_controls/access_control_edit.php index e5890dd82a..7045576535 100644 --- a/app/access_controls/access_control_edit.php +++ b/app/access_controls/access_control_edit.php @@ -202,7 +202,7 @@ //attempt digs if (!empty($digs) && is_array($digs)) { foreach ($digs as $dig) { - $response = shell_exec("dig +noall +answer ".$dig['value']." | awk '{ print $5 }'"); + $response = shell_exec("dig +noall +answer ".escapeshellarg($dig['value'])." | awk '{ print $5 }'"); if (!empty($response)) { $lines = explode("\n", $response); foreach ($lines as $l => $line) {