Security hardening: fix SQLi, XSS, file upload, and migrate DB to RDS
- Fix all SQL injection vulnerabilities across Service_model, User_model, Module_model, Log_model, and Admin controller using parameterized queries - Add htmlspecialchars() to all user-controlled output in admin views (bookings, services, workers, service categories, login form) - Fix XSS in AJAX worker response and manage-booking-cancelled view - Add file extension whitelist (jpg, jpeg, png, gif, webp) to all uploads - Remove webshell (pentest2.php) from assets/img/profiles/ - Stop logging plaintext passwords on failed login attempts - Migrate database.php hostname from localhost to AWS RDS endpoint - Fix dropdown styling (white-on-white) in worker calendar view Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
307f17faa6
commit
420bcb37fd
@@ -5,22 +5,22 @@
|
||||
<input type="hidden" name="booking_id" value="<?php echo $selectedItem->booking_id;?>">
|
||||
<div class="formRow">
|
||||
<label class="formTitle">Vendég neve</label>
|
||||
<input type="text" class="formInputBox" name="guest_name" value="<?php echo $selectedItem->guest_name;?>">
|
||||
<input type="text" class="formInputBox" name="guest_name" value="<?php echo htmlspecialchars($selectedItem->guest_name, ENT_QUOTES, 'UTF-8');?>">
|
||||
</div>
|
||||
<div class="formRow">
|
||||
<label class="formTitle">Email</label>
|
||||
<input type="text" class="formInputBox" name="guest_email" value="<?php echo $selectedItem->guest_email;?>">
|
||||
<input type="text" class="formInputBox" name="guest_email" value="<?php echo htmlspecialchars($selectedItem->guest_email, ENT_QUOTES, 'UTF-8');?>">
|
||||
</div>
|
||||
<div class="formRow">
|
||||
<label class="formTitle">Telefon</label>
|
||||
<input type="text" class="formInputBox" name="guest_phone" value="<?php echo $selectedItem->guest_phone;?>">
|
||||
<input type="text" class="formInputBox" name="guest_phone" value="<?php echo htmlspecialchars($selectedItem->guest_phone, ENT_QUOTES, 'UTF-8');?>">
|
||||
</div>
|
||||
<div class="formRow">
|
||||
<label class="formTitle">Dolgozó</label>
|
||||
<select class="formDropdownBox" style="padding:0;" name="worker_id" id="worker_id">
|
||||
<?php
|
||||
foreach($workers as $workerItem){
|
||||
echo '<option value="'.$workerItem->worker_id.'" '.($workerItem->worker_id == $selectedItem->worker_id?'selected':'').'>'.$workerItem->worker_name.'</option>';
|
||||
echo '<option value="'.htmlspecialchars($workerItem->worker_id, ENT_QUOTES, 'UTF-8').'" '.($workerItem->worker_id == $selectedItem->worker_id?'selected':'').'>'.htmlspecialchars($workerItem->worker_name, ENT_QUOTES, 'UTF-8').'</option>';
|
||||
}
|
||||
?>
|
||||
</select>
|
||||
|
||||
Reference in New Issue
Block a user