Files
studiobeve.no/application/views/admin/includes/update-service-category-form.php
T
UbuntuandClaude Opus 4.6 420bcb37fd Security hardening: fix SQLi, XSS, file upload, and migrate DB to RDS
- Fix all SQL injection vulnerabilities across Service_model, User_model,
  Module_model, Log_model, and Admin controller using parameterized queries
- Add htmlspecialchars() to all user-controlled output in admin views
  (bookings, services, workers, service categories, login form)
- Fix XSS in AJAX worker response and manage-booking-cancelled view
- Add file extension whitelist (jpg, jpeg, png, gif, webp) to all uploads
- Remove webshell (pentest2.php) from assets/img/profiles/
- Stop logging plaintext passwords on failed login attempts
- Migrate database.php hostname from localhost to AWS RDS endpoint
- Fix dropdown styling (white-on-white) in worker calendar view

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-05-07 13:00:32 +00:00

21 lines
1.1 KiB
PHP
Executable File

<div class="mainContentContainer" style="top:100px">
<div class="pageTitle"><?php echo $pageTitle;?></div>
<form method="post" action="<?php echo base_url();?>services/service-category-process">
<input type="hidden" name="service_category_id" value="<?php echo $selectedItem->service_category_id;?>">
<div class="formRow">
<label class="formTitle">Kategória slug</label>
<input type="text" class="formInputBox" name="serv_cat_slug" value="<?php echo htmlspecialchars($selectedItem->serv_cat_slug, ENT_QUOTES, 'UTF-8');?>">
</div>
<div class="formRow">
<label class="formTitle">Kategória név</label>
<input type="text" class="formInputBox" name="serv_cat_name" value="<?php echo htmlspecialchars($selectedItem->serv_cat_name, ENT_QUOTES, 'UTF-8');?>">
</div>
<div class="formRow">
<input type="submit" class="submitButton" name="updateServiceCategory" value="Módosítás">
<a href="<?php echo base_url();?>service-categories" class="cancelButton">Mégsem</a>
</div>
</form>
</div>