Skip to:
Content

BuddyPress.org


Ignore:
Timestamp:
11/13/2021 06:40:37 PM (3 years ago)
Author:
espellcaste
Message:

Sanitize all ORDER BY (ASC/DESC) values using the bp_esc_sql_order helper function where possible.

BuddyPress is not consistent on how it escapes ORDER BY (ASC/DESC) values provided by the developers/users. This commit improves that by using the bp_esc_sql_order helper function where possible.

Props imath

Fixes #8576

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/src/bp-notifications/bp-notifications-template.php

    r13108 r13147  
    998998
    999999    // Check for a custom sort_order.
    1000     if ( !empty( $_REQUEST['sort_order'] ) ) {
    1001         if ( in_array( $_REQUEST['sort_order'], $orders ) ) {
     1000    if ( ! empty( $_REQUEST['sort_order'] ) ) {
     1001        if ( in_array( $_REQUEST['sort_order'], $orders, true ) ) {
    10021002            $selected = $_REQUEST['sort_order'];
    10031003        }
Note: See TracChangeset for help on using the changeset viewer.