Merge pull request #62 from cypherbits/fix-session-xss

Fix XSS in session variables.
This commit is contained in:
Daniel Winzen
2020-05-07 20:28:10 +02:00
committed by GitHub

View File

@ -45,6 +45,7 @@ load_config();
if(!isset($_REQUEST['session']) && isset($_COOKIE[COOKIENAME])){
$_REQUEST['session']=$_COOKIE[COOKIENAME];
}
$_REQUEST['session'] = preg_replace('/[^0-9a-zA-Z]/', '', $_REQUEST['session']);
load_lang();
check_db();
cron();