(cp 9755d88ed) fixes GHSA-hq29-8hhx-5jwc [search] check input parameter ratings

This commit is contained in:
plegall
2026-06-25 13:31:12 +02:00
parent af8a882db2
commit aede490a0b
2 changed files with 9 additions and 1 deletions
+8
View File
@@ -1039,6 +1039,14 @@ function ws_images_filteredSearch_create($params, $service)
if ($conf['rate'] and isset($params['ratings']))
{
foreach ($params['ratings'] as $rate)
{
if (!preg_match('/^\d+$/i', $rate))
{
return new PwgError(WS_ERR_INVALID_PARAM, 'Invalid parameter ratings');
}
}
$search['fields']['ratings'] = $params['ratings'];
}