mirror of
https://git.tt-rss.org/git/tt-rss.git
synced 2025-12-14 14:55:56 +00:00
authenticate_user: properly escape input
This commit is contained in:
@@ -1741,6 +1741,7 @@
|
|||||||
|
|
||||||
$pwd_hash1 = encrypt_password($password);
|
$pwd_hash1 = encrypt_password($password);
|
||||||
$pwd_hash2 = encrypt_password($password, $login);
|
$pwd_hash2 = encrypt_password($password, $login);
|
||||||
|
$login = db_escape_string($login);
|
||||||
|
|
||||||
if (defined('ALLOW_REMOTE_USER_AUTH') && ALLOW_REMOTE_USER_AUTH
|
if (defined('ALLOW_REMOTE_USER_AUTH') && ALLOW_REMOTE_USER_AUTH
|
||||||
&& $_SERVER["REMOTE_USER"] && $login != "admin") {
|
&& $_SERVER["REMOTE_USER"] && $login != "admin") {
|
||||||
|
|||||||
Reference in New Issue
Block a user