XSS prevent on sort_asc and eid. Still need to protect filter

pull/3812/head
Isaac Connor 2024-01-25 18:48:39 -05:00
parent b5757a2d05
commit c138984fc9
1 changed files with 2 additions and 2 deletions

View File

@ -1126,9 +1126,9 @@ function sortHeader($field, $querySep='&') {
'?view='.$view,
'page=1'.((isset($_REQUEST['filter']) and isset($_REQUEST['filter']['query'])) ? $_REQUEST['filter']['query'] : ''),
'sort_field='.$field,
'sort_asc='.( ( isset($_REQUEST['sort_field']) and ( $_REQUEST['sort_field'] == $field ) ) ? !$_REQUEST['sort_asc'] : 0),
'sort_asc='.( ( isset($_REQUEST['sort_field']) and ( $_REQUEST['sort_field'] == $field ) ) ? !validInt($_REQUEST['sort_asc']) : 0),
'limit='.(isset($_REQUEST['limit']) ? validInt($_REQUEST['limit']) : ''),
(isset($_REQUEST['eid']) ? 'eid='.$_REQUEST['eid'] : '' ),
(isset($_REQUEST['eid']) ? 'eid='.validCardinal($_REQUEST['eid']) : '' ),
));
}