Commit Graph
4 Commits
Author SHA1 Message Date
Isaac Connor 644716b4ea fix: sanitize reflected user input in ajax error messages
Earlier commits in this branch dropped reflected user input from
ajaxError() messages entirely to close Snyk XSS findings, but that
lost useful diagnostic information ("Unrecognised action <name>",
"Insufficient permissions for user <user>"). Use validHtmlStr()
(htmlspecialchars with ENT_QUOTES) so the values still appear in
the message and Snyk recognises the sanitization. Affects
add_monitors.php, device.php, event.php, events.php, log.php.
2026-05-13 22:54:02 -04:00
Isaac Connor 0451fdadf7 fix: remove reflected user input from device ajax XSS sinks
Both ajaxError() calls in device.php concatenated user-controlled
data ($_REQUEST['action'], $user->Username()) into the response
body. exit(jsonEncode(...)) is flagged by Snyk regardless of
Content-Type. Drop the reflected tokens; still log the action
server-side via ZM\\Warning.
2026-05-13 15:56:05 -04:00
Isaac Connor 969baa3891 Convert user from an array to a User object 2023-04-23 12:57:29 -04:00
Andrew Bauer 6c0f61ebbd rework devices view, remove inline onclick 2020-10-02 12:39:05 -05:00