Security hardening: fix SQLi, XSS, file upload, and migrate DB to RDS
- Fix all SQL injection vulnerabilities across Service_model, User_model, Module_model, Log_model, and Admin controller using parameterized queries - Add htmlspecialchars() to all user-controlled output in admin views (bookings, services, workers, service categories, login form) - Fix XSS in AJAX worker response and manage-booking-cancelled view - Add file extension whitelist (jpg, jpeg, png, gif, webp) to all uploads - Remove webshell (pentest2.php) from assets/img/profiles/ - Stop logging plaintext passwords on failed login attempts - Migrate database.php hostname from localhost to AWS RDS endpoint - Fix dropdown styling (white-on-white) in worker calendar view Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
307f17faa6
commit
420bcb37fd
@@ -29,23 +29,23 @@
|
||||
?>
|
||||
<tr>
|
||||
<td>
|
||||
<a href="<?php echo SITEURL;?>services/update-service/<?php echo $resultItem->service_id;?>"><i class="fas fa-edit"></i></a>
|
||||
<a href="<?php echo SITEURL;?>services/update-service/<?php echo htmlspecialchars($resultItem->service_id, ENT_QUOTES, 'UTF-8');?>"><i class="fas fa-edit"></i></a>
|
||||
| <a href="<?php echo site_url().'services/service-process?delete-service='.$resultItem->service_id;?>" onclick="return confirm('Valóban törölni szeretnéd?');"><i class="fas fa-trash-alt" style="font-size: 14px;color:#585858;"></i></a>
|
||||
</td>
|
||||
<td>#<?php echo $resultItem->service_id;?></td>
|
||||
<td><?php echo $resultItem->service_type;?></td>
|
||||
<td><?php echo $resultItem->service_category_no;?></td>
|
||||
<td><?php echo $resultItem->service_category_en;?></td>
|
||||
<td><?php echo $resultItem->service_category_hu;?></td>
|
||||
<td><?php echo $resultItem->service_name_no;?></td>
|
||||
<td><?php echo $resultItem->service_name_en;?></td>
|
||||
<td><?php echo $resultItem->service_name_hu;?></td>
|
||||
<td><?php echo $resultItem->service_description_no;?></td>
|
||||
<td><?php echo $resultItem->service_description_en;?></td>
|
||||
<td><?php echo $resultItem->service_description_hu;?></td>
|
||||
<td><?php echo $resultItem->service_price;?></td>
|
||||
<td><?php echo $resultItem->service_time;?></td>
|
||||
<td><?php echo $resultItem->serv_cat_name;?></td>
|
||||
<td>#<?php echo htmlspecialchars($resultItem->service_id, ENT_QUOTES, 'UTF-8');?></td>
|
||||
<td><?php echo htmlspecialchars($resultItem->service_type, ENT_QUOTES, 'UTF-8');?></td>
|
||||
<td><?php echo htmlspecialchars($resultItem->service_category_no, ENT_QUOTES, 'UTF-8');?></td>
|
||||
<td><?php echo htmlspecialchars($resultItem->service_category_en, ENT_QUOTES, 'UTF-8');?></td>
|
||||
<td><?php echo htmlspecialchars($resultItem->service_category_hu, ENT_QUOTES, 'UTF-8');?></td>
|
||||
<td><?php echo htmlspecialchars($resultItem->service_name_no, ENT_QUOTES, 'UTF-8');?></td>
|
||||
<td><?php echo htmlspecialchars($resultItem->service_name_en, ENT_QUOTES, 'UTF-8');?></td>
|
||||
<td><?php echo htmlspecialchars($resultItem->service_name_hu, ENT_QUOTES, 'UTF-8');?></td>
|
||||
<td><?php echo htmlspecialchars($resultItem->service_description_no, ENT_QUOTES, 'UTF-8');?></td>
|
||||
<td><?php echo htmlspecialchars($resultItem->service_description_en, ENT_QUOTES, 'UTF-8');?></td>
|
||||
<td><?php echo htmlspecialchars($resultItem->service_description_hu, ENT_QUOTES, 'UTF-8');?></td>
|
||||
<td><?php echo htmlspecialchars($resultItem->service_price, ENT_QUOTES, 'UTF-8');?></td>
|
||||
<td><?php echo htmlspecialchars($resultItem->service_time, ENT_QUOTES, 'UTF-8');?></td>
|
||||
<td><?php echo htmlspecialchars($resultItem->serv_cat_name, ENT_QUOTES, 'UTF-8');?></td>
|
||||
<td><?php echo $resultItem->is_enabled?'igen':'nem';?></td>
|
||||
</tr>
|
||||
<?php
|
||||
|
||||
Reference in New Issue
Block a user