From fb376fe3faf639d0a18a06eb3e1432e7e281fa98 Mon Sep 17 00:00:00 2001 From: cytopia Date: Sat, 28 Jul 2018 09:21:43 +0200 Subject: [PATCH] Fix #326 XSS vulnerability in email display --- .devilbox/www/htdocs/mail.php | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/.devilbox/www/htdocs/mail.php b/.devilbox/www/htdocs/mail.php index 412b62d3..46bcdbd3 100644 --- a/.devilbox/www/htdocs/mail.php +++ b/.devilbox/www/htdocs/mail.php @@ -157,7 +157,7 @@ $messages = $MyMbox->get($sortOrderArr); @@ -167,17 +167,17 @@ $messages = $MyMbox->get($sortOrderArr); headers['date']));?> headers['from']);?> - headers['x-original-to'];?> - headers['subject'];?> + headers['x-original-to']);?> + headers['subject']);?> body)): ?> - body ?> + body) ?> parts[1]->body)): ?> - parts[1]->body ?> + parts[1]->body) ?> parts[0]->body)): ?> parts[0]->body) ?>