Minor security fix for XSS vulnerability - previously mitigated by CSP

This commit is contained in:
2025-12-25 20:33:23 +01:00
parent a6bd50a7be
commit e017b5c883

View File

@@ -2228,14 +2228,14 @@ function send_del_confirm(): void
echo hidden('multi', 'on');
}
if(isset($_POST['sendto'])){
echo hidden('sendto', $_POST['sendto']);
echo hidden('sendto', htmlspecialchars($_POST['sendto']));
}
echo hidden('confirm', 'yes').hidden('what', $_POST['what']).submit(_('Yes'), 'class="delbutton"').'</form></td><td>'.form('post');
echo hidden('confirm', 'yes').hidden('what', htmlspecialchars($_POST['what'])).submit(_('Yes'), 'class="delbutton"').'</form></td><td>'.form('post');
if(isset($_POST['multi'])){
echo hidden('multi', 'on');
}
if(isset($_POST['sendto'])){
echo hidden('sendto', $_POST['sendto']);
echo hidden('sendto', htmlspecialchars($_POST['sendto']));
}
echo submit(_('No'), 'class="backbutton"').'</form></td><tr></table>';
print_end();