From 16420044ac0301b26aaa67d8973df0258eb90cbb Mon Sep 17 00:00:00 2001 From: Matthieu Leproux Date: Wed, 28 Sep 2022 15:26:39 +0200 Subject: [PATCH] related to #1470 added id input check --- admin/albums.php | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/admin/albums.php b/admin/albums.php index c5911d660..5022b0bac 100644 --- a/admin/albums.php +++ b/admin/albums.php @@ -49,7 +49,8 @@ if (isset($_POST['simpleAutoOrder']) || isset($_POST['recursiveAutoOrder']) ) { die('Invalid sort order'); } - + check_input_parameter('id', $_POST, false, '/^-?\d+$/'); + $query = ' SELECT id FROM '.CATEGORIES_TABLE.'