Skip to content
Snippets Groups Projects
Commit 1f8c35b7 authored by Laurent Destailleur's avatar Laurent Destailleur
Browse files

Fix: security

parent baa57343
No related branches found
No related tags found
No related merge requests found
...@@ -54,16 +54,23 @@ print '</div>'; ...@@ -54,16 +54,23 @@ print '</div>';
print '<div class="principal">'; print '<div class="principal">';
if ( $_GET['menu'] ) $page=GETPOST('menu','alpha');
if (in_array(
$page,
array(
'deconnexion',
'index','index_verif','facturation','facturation_verif','facturation_dhtml',
'validation','validation_ok','validation_ticket','validation_verif',
)
))
{ {
include $_GET['menu'].'.php'; include $page.'.php';
} }
else else
{ {
include 'facturation.php'; dol_print_error('','menu param '.$page.' is not inside allowed list');
} }
print '</div>'; print '</div>';
$_SESSION['serObjFacturation'] = serialize($obj_facturation); $_SESSION['serObjFacturation'] = serialize($obj_facturation);
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment