Commit 52ebaf93 authored by Andrew Dolgov's avatar Andrew Dolgov

api/updateArticle: validate article_ids parameter (refs #375)

parent e894e97f
......@@ -207,7 +207,7 @@
break;
case "updateArticle":
$article_ids = split(",", db_escape_string($_REQUEST["article_ids"]));
$article_ids = array_filter(explode(",", db_escape_string($_REQUEST["article_ids"])), is_numeric);
$mode = (int) db_escape_string($_REQUEST["mode"]);
$field_raw = (int)db_escape_string($_REQUEST["field"]);
......
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment