Fix injection vulnerability in fdb search page (#15315)

unescaped search output
reported by: https://huntr.dev/users/hainguyen0207
This commit is contained in:
Tony Murray
2023-09-14 00:22:42 -05:00
committed by GitHub
parent cfd642be6a
commit 2c5960631c

View File

@@ -112,7 +112,7 @@ if ($vars['searchby'] == 'vlan') {
"<div class=\"form-group\">"+
"<input type=\"text\" name=\"searchPhrase\" id=\"address\" value=\""+
<?php
echo '"' . $vars['searchPhrase'] . '"+';
echo '"' . htmlspecialchars($vars['searchPhrase']) . '"+';
?>
"\" class=\"form-control input-sm\" placeholder=\"Value\" />"+