mirror of
https://github.com/Piwigo/Piwigo.git
synced 2026-03-28 17:42:57 +01:00
fixes GHSA-5jwg-cr5q-vjq2 protect filter parameter in pwg.user.getList
This commit is contained in:
@@ -58,7 +58,7 @@ function ws_users_getList($params, &$service)
|
||||
$filtered_groups = array();
|
||||
if (!empty($params['filter']))
|
||||
{
|
||||
$filter_query = 'SELECT id FROM `'. GROUPS_TABLE .'` WHERE name LIKE \'%'. $params['filter'] . '%\';';
|
||||
$filter_query = 'SELECT id FROM `'. GROUPS_TABLE .'` WHERE name LIKE \'%'. pwg_db_real_escape_string($params['filter']) . '%\';';
|
||||
$filtered_groups_res = pwg_query($filter_query);
|
||||
while ($row = pwg_db_fetch_assoc($filtered_groups_res))
|
||||
{
|
||||
|
||||
Reference in New Issue
Block a user