Skip to content
Snippets Groups Projects
Commit 1f8c35b7 authored by Laurent Destailleur's avatar Laurent Destailleur
Browse files

Fix: security

parent baa57343
No related branches found
No related tags found
No related merge requests found
......@@ -54,16 +54,23 @@ print '</div>';
print '<div class="principal">';
if ( $_GET['menu'] )
$page=GETPOST('menu','alpha');
if (in_array(
$page,
array(
'deconnexion',
'index','index_verif','facturation','facturation_verif','facturation_dhtml',
'validation','validation_ok','validation_ticket','validation_verif',
)
))
{
include $_GET['menu'].'.php';
include $page.'.php';
}
else
{
include 'facturation.php';
dol_print_error('','menu param '.$page.' is not inside allowed list');
}
print '</div>';
$_SESSION['serObjFacturation'] = serialize($obj_facturation);
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment