Minor security fix for XSS vulnerability - previously mitigated by CSP

This commit is contained in:
2025-12-25 20:33:23 +01:00
parent a6bd50a7be
commit e017b5c883

View File

@@ -2228,14 +2228,14 @@ function send_del_confirm(): void
echo hidden('multi', 'on'); echo hidden('multi', 'on');
} }
if(isset($_POST['sendto'])){ if(isset($_POST['sendto'])){
echo hidden('sendto', $_POST['sendto']); echo hidden('sendto', htmlspecialchars($_POST['sendto']));
} }
echo hidden('confirm', 'yes').hidden('what', $_POST['what']).submit(_('Yes'), 'class="delbutton"').'</form></td><td>'.form('post'); echo hidden('confirm', 'yes').hidden('what', htmlspecialchars($_POST['what'])).submit(_('Yes'), 'class="delbutton"').'</form></td><td>'.form('post');
if(isset($_POST['multi'])){ if(isset($_POST['multi'])){
echo hidden('multi', 'on'); echo hidden('multi', 'on');
} }
if(isset($_POST['sendto'])){ if(isset($_POST['sendto'])){
echo hidden('sendto', $_POST['sendto']); echo hidden('sendto', htmlspecialchars($_POST['sendto']));
} }
echo submit(_('No'), 'class="backbutton"').'</form></td><tr></table>'; echo submit(_('No'), 'class="backbutton"').'</form></td><tr></table>';
print_end(); print_end();