The workshop-application handler assigned $_POST['hidden_id'] straight into $app['user_id'], which is then concatenated unescaped into two SELECT statements (user_id=" . $app['user_id']). An attacker could inject SQL through the hidden_id POST field. user_id is a numeric key everywhere else in this same file (e.g. line 89 already uses (int)$_POST['user_id']); applying the same (int) cast closes the injection with no behaviour change. Assisted-by: claude-code@claude-opus-4-8 |
||
|---|---|---|
| .. | ||
| mod_al_applications | ||
| mod_al_login | ||
| mod_al_newsletter | ||
| mod_al_upload | ||
| mod_al_vote | ||
| mod_alusers | ||
| mod_alworkshops | ||
| mod_course_list | ||
| mod_webinar | ||
| mod_webinar_list | ||
| mod_wsregister | ||