From: Frank Karlitschek Date: Sun, 6 May 2012 21:06:38 +0000 (+0200) Subject: fix an XSS bug X-Git-Tag: v4.0.0beta~3 X-Git-Url: https://source.dussan.org/?a=commitdiff_plain;h=d2b0de614eb3bbcdb2eae90929af48a69777f49c;p=nextcloud-server.git fix an XSS bug --- diff --git a/index.php b/index.php index b9872a906d7..91f0cfb5e48 100644 --- a/index.php +++ b/index.php @@ -115,6 +115,6 @@ elseif(OC_User::isLoggedIn()) { if(is_null(OC::$REQUESTEDFILE)){ $sectoken=rand(1000000,9999999); $_SESSION['sectoken']=$sectoken; - OC_Template::printGuestPage('', 'login', array('error' => $error, 'sectoken' => $sectoken, 'redirect' => isset($_REQUEST['redirect_url'])?$_REQUEST['redirect_url']:'' )); + OC_Template::printGuestPage('', 'login', array('error' => $error, 'sectoken' => $sectoken, 'redirect' => isset($_REQUEST['redirect_url'])?strip_tags($_REQUEST['redirect_url']):'' )); } }