Skip to content

Commit

Permalink
[BUGFIX] sanitize searchString to prevent XSS attacks.
Browse files Browse the repository at this point in the history
  • Loading branch information
Max Frerichs committed May 21, 2024
1 parent 3d707cf commit bbb4aba
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion Classes/Controller/SearchController.php
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ class SearchController extends ActionController
{
public function searchAction()
{
$searchString = $this->request->getQueryParams()[($this->settings['parameters']['search'] ?? 'q')];
$searchString = htmlspecialchars(strip_tags($this->request->getQueryParams()[($this->settings['parameters']['search'] ?? 'q')]), ENT_QUOTES, 'UTF-8');
$currentPage = $this->request->getQueryParams()[($this->settings['parameters']['page'] ?? 'p')];
$currentPage = max(1, $currentPage ? (int)$currentPage : 1);
$category = $this->request->getQueryParams()[($this->settings['parameters']['category'] ?? 'c')];
Expand Down

0 comments on commit bbb4aba

Please sign in to comment.