mirror of
https://github.com/librenms/librenms.git
synced 2024-10-07 16:52:45 +00:00
XSS fixes (#13780)
This commit is contained in:
@@ -34,7 +34,7 @@ if (! Auth::check()) {
|
||||
$status = 'error';
|
||||
$message = 'unknown error';
|
||||
|
||||
$dashboard_name = trim($_REQUEST['dashboard_name']);
|
||||
$dashboard_name = trim(strip_tags($_REQUEST['dashboard_name']));
|
||||
|
||||
if (! empty($dashboard_name) && ($dash_id = dbInsert(['dashboard_name' => $dashboard_name, 'user_id' => Auth::id()], 'dashboards'))) {
|
||||
$status = 'ok';
|
||||
|
||||
@@ -17,9 +17,9 @@ $message = '';
|
||||
$device_id = $_POST['device_id'];
|
||||
$id = $_POST['ccustomoid_id'];
|
||||
$action = $_POST['action'];
|
||||
$name = $_POST['name'];
|
||||
$oid = $_POST['oid'];
|
||||
$datatype = $_POST['datatype'];
|
||||
$name = strip_tags($_POST['name']);
|
||||
$oid = strip_tags($_POST['oid']);
|
||||
$datatype = strip_tags($_POST['datatype']);
|
||||
if (empty(($_POST['unit']))) {
|
||||
$unit = ['NULL'];
|
||||
} else {
|
||||
|
||||
@@ -35,7 +35,7 @@ $status = 'ok';
|
||||
$message = '';
|
||||
|
||||
$group_id = $vars['group_id'];
|
||||
$name = $vars['name'];
|
||||
$name = strip_tags($vars['name']);
|
||||
|
||||
$target_members = [];
|
||||
foreach ((array) $vars['members'] as $target) {
|
||||
|
||||
Reference in New Issue
Block a user