firewall: fix potential XSS

Spotted by: @fabianfrz
This commit is contained in:
Franco Fichtner 2016-03-17 10:59:35 +01:00
parent b1034aab94
commit ff6f234102

View File

@ -231,7 +231,7 @@ if ($_SERVER['REQUEST_METHOD'] === 'GET') {
}
}
$referer = (isset($_SERVER['HTTP_REFERER']) ? $_SERVER['HTTP_REFERER'] : '/firewall_aliases.php');
$referer = (isset($_SERVER['HTTP_REFERER']) ? html_safe($_SERVER['HTTP_REFERER']) : '/firewall_aliases.php');
legacy_html_escape_form_data($pconfig);