Skip to content
Permalink
Browse files

issue #1150 also protect groupe name on API methods

  • Loading branch information
plegall committed Feb 7, 2020
1 parent 619849f commit 6ac6db0d2da3ba43f1203751afd34ce7353944be
Showing with 2 additions and 2 deletions.
  1. +2 −2 include/ws_functions/pwg.groups.php
@@ -61,7 +61,7 @@ function ws_groups_getList($params, &$service)
*/
function ws_groups_add($params, &$service)
{
$params['name'] = pwg_db_real_escape_string($params['name']);
$params['name'] = pwg_db_real_escape_string(strip_tags(stripslashes($params['name'])));

// is the name not already used ?
$query = '
@@ -180,7 +180,7 @@ function ws_groups_setInfo($params, &$service)

if (!empty($params['name']))
{
$params['name'] = pwg_db_real_escape_string($params['name']);
$params['name'] = pwg_db_real_escape_string(strip_tags(stripslashes($params['name'])));

// is the name not already used ?
$query = '

0 comments on commit 6ac6db0

Please sign in to comment.
You can’t perform that action at this time.