From 90c5cdd97ca92e0f82e49c5cca5a27b93139eb7d Mon Sep 17 00:00:00 2001 From: Ferywir <65760459+Ferywir@users.noreply.github.com> Date: Tue, 23 Jun 2026 16:59:00 +0200 Subject: [PATCH] fix(admin): escape reflected filter param in report/msg templates [#139] (#271) --- Admin/Templates/msg.tpl | 4 ++-- Admin/Templates/report.tpl | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/Admin/Templates/msg.tpl b/Admin/Templates/msg.tpl index a478fbee..ce0caefd 100644 --- a/Admin/Templates/msg.tpl +++ b/Admin/Templates/msg.tpl @@ -128,7 +128,7 @@ $msgs = $database->query("SELECT * FROM ".TB_PREFIX."mdata WHERE $where ORDER BY
@@ -162,7 +162,7 @@ $msgs = $database->query("SELECT * FROM ".TB_PREFIX."mdata WHERE $where ORDER BY $limit){ $pages = ceil($total/$limit);?> diff --git a/Admin/Templates/report.tpl b/Admin/Templates/report.tpl index de58368f..27a57367 100644 --- a/Admin/Templates/report.tpl +++ b/Admin/Templates/report.tpl @@ -102,7 +102,7 @@ $typeNames = [1=>'reinforcement',2=>'attack',3=>'defence',4=>'scout',5=>'trade', @@ -134,7 +134,7 @@ $typeNames = [1=>'reinforcement',2=>'attack',3=>'defence',4=>'scout',5=>'trade', $limit){ $pages = ceil($total/$limit);?>