fix(mod_alworkshops): cast hidden_id to int to close SQL injection
The workshop-application handler assigned $_POST['hidden_id'] straight into $app['user_id'], which is then concatenated unescaped into two SELECT statements (user_id=" . $app['user_id']). An attacker could inject SQL through the hidden_id POST field. user_id is a numeric key everywhere else in this same file (e.g. line 89 already uses (int)$_POST['user_id']); applying the same (int) cast closes the injection with no behaviour change. Assisted-by: claude-code@claude-opus-4-8
This commit is contained in:
parent
974beee429
commit
8a9d865edc
@ -187,7 +187,7 @@ class Controller extends BaseController
|
|||||||
}
|
}
|
||||||
|
|
||||||
// application rekord mentés
|
// application rekord mentés
|
||||||
$app['user_id'] = $_POST['hidden_id'];
|
$app['user_id'] = (int)$_POST['hidden_id'];
|
||||||
$app['name'] = trim(addslashes(ucwords($_POST['usr'])));
|
$app['name'] = trim(addslashes(ucwords($_POST['usr'])));
|
||||||
$app['email'] = trim(addslashes($_POST['email']));
|
$app['email'] = trim(addslashes($_POST['email']));
|
||||||
MySqlHelper::getInstance()->insert('alworkshops_application', $app);
|
MySqlHelper::getInstance()->insert('alworkshops_application', $app);
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user