From 548698e760eeca2abbafe2a38f77e2202f9c013b Mon Sep 17 00:00:00 2001 From: plegall Date: Fri, 19 Oct 2012 20:16:52 +0000 Subject: merge r18699 from branch 2.4 to trunk bug 2774 fixed: better sanitize on username_or_email user input git-svn-id: http://piwigo.org/svn/trunk@18700 68402e56-0260-453c-a942-63ccdbb3a9ee --- password.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'password.php') diff --git a/password.php b/password.php index fd3717151..845a00a3d 100644 --- a/password.php +++ b/password.php @@ -326,7 +326,7 @@ if ('lost' == $page['action']) if (isset($_POST['username_or_email'])) { - $template->assign('username_or_email', stripslashes(strip_tags($_POST['username_or_email']))); + $template->assign('username_or_email', htmlspecialchars(stripslashes($_POST['username_or_email']))); } } -- cgit v1.2.3