www_archline_hu/cadline
imre.agent 8a9d865edc fix(mod_alworkshops): cast hidden_id to int to close SQL injection
The workshop-application handler assigned $_POST['hidden_id'] straight into $app['user_id'], which is then concatenated unescaped into two SELECT statements (user_id=" . $app['user_id']). An attacker could inject SQL through the hidden_id POST field.

user_id is a numeric key everywhere else in this same file (e.g. line 89 already uses (int)$_POST['user_id']); applying the same (int) cast closes the injection with no behaviour change.

Assisted-by: claude-code@claude-opus-4-8
2026-07-22 11:02:59 +02:00
..
backend chore(submodules): bump backend submodules to 2026-07-17 state 2026-07-21 18:49:51 +02:00
components chore: renormalize stored line endings to LF per .gitattributes 2026-07-21 18:46:11 +02:00
docroot chore: renormalize stored line endings to LF per .gitattributes 2026-07-21 18:46:11 +02:00
modules/modules fix(mod_alworkshops): cast hidden_id to int to close SQL injection 2026-07-22 11:02:59 +02:00
tmpl-plg chore: renormalize stored line endings to LF per .gitattributes 2026-07-21 18:46:11 +02:00
.gitkeep build(baseline): constituents+generator skeleton 2026-07-16 09:40:46 +02:00