merge r18699 from branch 2.4 to trunk

bug 2774 fixed: better sanitize on username_or_email user input


git-svn-id: http://piwigo.org/svn/trunk@18700 68402e56-0260-453c-a942-63ccdbb3a9ee
This commit is contained in:
plegall
2012-10-19 20:16:52 +00:00
parent 248784ff18
commit 548698e760

View File

@@ -326,7 +326,7 @@ if ('lost' == $page['action'])
if (isset($_POST['username_or_email']))
{
$template->assign('username_or_email', stripslashes(strip_tags($_POST['username_or_email'])));
$template->assign('username_or_email', htmlspecialchars(stripslashes($_POST['username_or_email'])));
}
}