mirror of
https://github.com/opensourcepos/opensourcepos.git
synced 2026-03-10 03:00:09 -04:00
- Add whitelist validation for invoice_type to prevent path traversal and LFI - Validate invoice_type against allowed values in Sale_lib - Sanitize invoice_type input in Config controller before saving - Default to 'invoice' template for invalid types Security: Prevents arbitrary file inclusion via user-controlled invoice_type config
72 KiB
72 KiB