fixes #572, check $_GET['mode'] against hacking attempt

This commit is contained in:
plegall
2016-12-19 11:33:09 +01:00
parent 5473f057b0
commit 9dd92959f6
+1
View File
@@ -593,6 +593,7 @@ $manager_link = get_root_url().'admin.php?page=batch_manager&mode=';
if (isset($_GET['mode']))
{
check_input_parameter('mode', $_GET, false, '/^(global|unit)$/');
$page['tab'] = $_GET['mode'];
}
else