FSN#39950 PENTEST Reflected XSS in sso parameter
svn path=/Website/branches/v2016.3/; revision=33318
This commit is contained in:
@@ -223,7 +223,7 @@ if (user_key < 0 && sso && sso != "0") // "0" is een hardcoded special case
|
||||
+ " WHERE fac_idp_code = " + safe.quoted_sql(sso);
|
||||
var oRs = Oracle.Execute(sql);
|
||||
if (oRs.Eof)
|
||||
shared.internal_error("Identity provider '{0}' is not configured for {1}".format(sso, customerId));
|
||||
shared.internal_error("Identity provider '{0}' is not configured for {1}".format(safe.html(sso), customerId));
|
||||
|
||||
var isFACFACinternal = oRs("fac_idp_internal").Value != 0;
|
||||
var ip_restrict = oRs("fac_idp_ipfilter").Value;
|
||||
|
||||
Reference in New Issue
Block a user