mirror of
https://github.com/pfsense/pfsense.git
synced 2025-10-26 11:38:35 +00:00
Encode the if parameter before using it in redirects, too.
This commit is contained in:
parent
52ab0384ca
commit
ee8981553b
@ -210,7 +210,7 @@ if ($_GET['act'] == "del") {
|
||||
unset($a_filter[$_GET['id']]);
|
||||
write_config();
|
||||
mark_subsystem_dirty('filter');
|
||||
header("Location: firewall_rules.php?if={$if}");
|
||||
header("Location: firewall_rules.php?if=" . htmlspecialchars($if));
|
||||
exit;
|
||||
}
|
||||
}
|
||||
@ -228,7 +228,7 @@ if (isset($_POST['del_x'])) {
|
||||
}
|
||||
write_config();
|
||||
mark_subsystem_dirty('filter');
|
||||
header("Location: firewall_rules.php?if={$if}");
|
||||
header("Location: firewall_rules.php?if=" . htmlspecialchars($if));
|
||||
exit;
|
||||
}
|
||||
} else if ($_GET['act'] == "toggle") {
|
||||
@ -239,7 +239,7 @@ if (isset($_POST['del_x'])) {
|
||||
$a_filter[$_GET['id']]['disabled'] = true;
|
||||
write_config();
|
||||
mark_subsystem_dirty('filter');
|
||||
header("Location: firewall_rules.php?if={$if}");
|
||||
header("Location: firewall_rules.php?if=" . htmlspecialchars($if));
|
||||
exit;
|
||||
}
|
||||
} else {
|
||||
@ -283,7 +283,7 @@ if (isset($_POST['del_x'])) {
|
||||
$a_filter = $a_filter_new;
|
||||
write_config();
|
||||
mark_subsystem_dirty('filter');
|
||||
header("Location: firewall_rules.php?if={$if}");
|
||||
header("Location: firewall_rules.php?if=" . htmlspecialchars($if));
|
||||
exit;
|
||||
}
|
||||
}
|
||||
|
||||
Loading…
Reference in New Issue
Block a user