@@ -15,6 +15,7 @@ if (empty($_GET['database'])) {
// Edit as someone else?
if (($_SESSION['userContext'] === 'admin') && (!empty($_GET['user']))) {
$user=escapeshellarg($_GET['user']);
+ $user_plain=htmlentities($_GET['user']);
}
// List datbase
@@ -15,6 +15,7 @@ if (empty($_GET['domain'])) {
// List ip addresses
$v_username = $user;
@@ -16,6 +16,7 @@ if (empty($_GET['domain'])) {
// Get all user domains
@@ -857,7 +857,7 @@
<tr>
<td class="vst-text step-top">
<?=_('SSL Certificate');?>
- <span id="generate-csr"> / <a class="generate" target="_blank" href="/generate/ssl/?domain=<?=$v_hostname?>"><?=_('Generate CSR');?></a></span>
+ <span id="generate-csr"> / <a class="generate" target="_blank" href="/generate/ssl/?domain=<?=htmlentities(trim($v_hostname,'"'));?>"><?=_('Generate CSR');?></a></span>
</td>
</tr>