I think htmlspecialchars should be used here
This commit is contained in:
@@ -108,7 +108,7 @@ if ($import_type == 'table') {
|
|||||||
}
|
}
|
||||||
$err_url = $goto
|
$err_url = $goto
|
||||||
. '?' . $common
|
. '?' . $common
|
||||||
. (preg_match('@^tbl_[a-z]*\.php$@', $goto) ? '&table=' . urlencode($table) : '');
|
. (preg_match('@^tbl_[a-z]*\.php$@', $goto) ? '&table=' . htmlspecialchars($table) : '');
|
||||||
$_SESSION['Import_message']['go_back_url'] = $err_url;
|
$_SESSION['Import_message']['go_back_url'] = $err_url;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
Reference in New Issue
Block a user