Commit e40fae0d authored by jouni%heikniemi.net's avatar jouni%heikniemi.net

Bug 224021: taint issues in editusers.cgi

Patch by byron jones <bugzilla@glob.com.au> r=jouni, a=justdave
parent 39e9e3e6
......@@ -323,6 +323,7 @@ if ($action eq 'list') {
$query = "SELECT login_name,realname,disabledtext " .
"FROM profiles WHERE " . $::FORM{'query'} . " ORDER BY login_name";
} elsif (exists $::FORM{'group'}) {
detaint_natural($::FORM{'group'});
$query = "SELECT DISTINCT login_name,realname,disabledtext " .
"FROM profiles, user_group_map WHERE profiles.userid = user_group_map.user_id
AND group_id=" . $::FORM{'group'} . " ORDER BY login_name";
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment