Skip to content

Commit b2d581f

Browse files
committed
#671 - sanitise email address of an admin
1 parent ec874b7 commit b2d581f

File tree

2 files changed

+2
-1
lines changed

2 files changed

+2
-1
lines changed

public_html/lists/admin/admin.php

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -89,6 +89,7 @@
8989
if ($id) {
9090
echo '<div class="actionresult">';
9191
reset($struct);
92+
$_POST['email'] = htmlspecialchars(strip_tags($_POST['email']));
9293
foreach ($struct as $key => $val) {
9394
$a = $b = '';
9495
if (strstr($val[1], ':')) {

public_html/lists/admin/admins.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -108,7 +108,7 @@
108108
$ls->addElement(htmlentities($admin['loginname']),
109109
PageUrl2('admin', s('Show'), "start=$start&amp;id=".$admin['id'].$remember_find));
110110
$ls->addColumn($admin['loginname'], s('Id'), $admin['id']);
111-
$ls->addColumn($admin['loginname'], s('email'), $admin['email']);
111+
$ls->addColumn($admin['loginname'], s('email'), htmlspecialchars($admin['email']));
112112
$ls->addColumn($admin['loginname'], s('Super Admin'), $admin['superuser'] ? s('Yes') : s('No'));
113113
$ls->addColumn($admin['loginname'], s('Disabled'), $admin['disabled'] ? s('Yes') : s('No'));
114114
if ($_SESSION['logindetails']['superuser'] && $admin['id'] != $_SESSION['logindetails']['id']) {

0 commit comments

Comments
 (0)