Prevent XSS throu mids

This commit is contained in:
Isaac Connor
2024-01-25 19:12:37 -05:00
parent f1a26b90b6
commit bf32bd6926

View File

@@ -23,7 +23,7 @@ if ( isset($_REQUEST['mid']) ) {
$mids = array();
$mids[] = validInt($_REQUEST['mid']);
} else if ( isset($_REQUEST['mids']) ) {
$mids = $_REQUEST['mids'];
$mids = arrap_map(function($thing){return validInt($thing);}, $_REQUEST['mids'] );
} else {
$mids = dbFetchAll('SELECT Id FROM Monitors'.($user->unviewableMonitorIds() ? 'WHERE Id IN ('.$user->viewableMonitorIds().')' : ''), 'Id');
}