Skip to content

Commit ebca9b1

Browse files
orthaghtrasher
authored andcommitted
escape fields when using addme_[assign|observer]
1 parent ff380cb commit ebca9b1

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

front/ticket.form.php

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -155,7 +155,7 @@
155155

156156
} else if (isset($_POST['addme_observer'])) {
157157
$track->check($_POST['tickets_id'], READ);
158-
$input = array_merge($track->fields, [
158+
$input = array_merge(Toolbox::addslashes_deep($track->fields), [
159159
'id' => $_POST['tickets_id'],
160160
'_itil_observer' => [
161161
'_type' => "user",
@@ -171,7 +171,7 @@
171171

172172
} else if (isset($_POST['addme_assign'])) {
173173
$track->check($_POST['tickets_id'], READ);
174-
$input = array_merge($track->fields, [
174+
$input = array_merge(Toolbox::addslashes_deep($track->fields), [
175175
'id' => $_POST['tickets_id'],
176176
'_itil_assign' => [
177177
'_type' => "user",

0 commit comments

Comments
 (0)