From bf4626da931b5120762f899cbcb42034244856ed Mon Sep 17 00:00:00 2001 From: Frank Karlitschek Date: Sun, 10 Jun 2012 19:52:23 +0200 Subject: [PATCH] prevent XSS --- apps/external/ajax/setsites.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/external/ajax/setsites.php b/apps/external/ajax/setsites.php index c758a3508c..772863974a 100644 --- a/apps/external/ajax/setsites.php +++ b/apps/external/ajax/setsites.php @@ -12,7 +12,7 @@ OCP\User::checkAdminUser(); $sites = array(); for ($i = 0; $i < sizeof($_POST['site_name']); $i++) { if (!empty($_POST['site_name'][$i]) && !empty($_POST['site_url'][$i])) { - array_push($sites, array($_POST['site_name'][$i], $_POST['site_url'][$i])); + array_push($sites, array(strip_tags($_POST['site_name'][$i]), strip_tags($_POST['site_url'][$i]))); } }