Skip to content

Commit 74e574c

Browse files
committed
escape the loginname value
Signed-off-by: Michiel Dethmers <[email protected]>
1 parent 1345169 commit 74e574c

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

public_html/lists/admin/importadmin.php

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -213,15 +213,15 @@
213213
privileges = "%s"
214214
where id = %d',
215215
$tables['admin'], sql_escape($email), sql_escape($loginname),
216-
normalize($loginname), adminName($_SESSION['logindetails']['id']),
216+
sql_escape(normalize($loginname)), adminName($_SESSION['logindetails']['id']),
217217
encryptPass($data['password']), sql_escape(serialize($privs)), $adminid);
218218
$result = Sql_query($query);
219219
} else {
220220
$query = sprintf('INSERT INTO %s
221221
(email,loginname,namelc,created,modifiedby,passwordchanged,password,superuser,disabled,privileges)
222222
values("%s","%s","%s",now(),"%s",now(),"%s",0,0,"%s")',
223223
$tables['admin'], sql_escape($email), sql_escape($loginname),
224-
normalize($loginname), adminName($_SESSION['logindetails']['id']),
224+
sql_escape(normalize($loginname)), adminName($_SESSION['logindetails']['id']),
225225
encryptPass($data['password']), sql_escape(serialize($privs)));
226226
$result = Sql_query($query);
227227
$adminid = Sql_insert_id();

0 commit comments

Comments
 (0)