- do not allow raw SQL through array[SQL] in db lib
- don't make sql request on invalid arguments in password reset form
Showing
- interface/lib/classes/db_mysql.inc.php 16 additions, 20 deletionsinterface/lib/classes/db_mysql.inc.php
- interface/web/login/password_reset.php 8 additions, 6 deletionsinterface/web/login/password_reset.php
- server/lib/classes/cron.d/300-quota_notify.inc.php 3 additions, 3 deletionsserver/lib/classes/cron.d/300-quota_notify.inc.php
- server/lib/classes/db_mysql.inc.php 16 additions, 20 deletionsserver/lib/classes/db_mysql.inc.php
Loading
Please register or sign in to comment