From 6cd5261a7d01debaeeb7f8976f2a2ecd9572ecc9 Mon Sep 17 00:00:00 2001 From: David Saez Date: Tue, 22 Feb 2022 08:30:21 +0100 Subject: [PATCH] Sanitize input --- example.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/example.php b/example.php index 952c96f..3fb8aec 100644 --- a/example.php +++ b/example.php @@ -35,7 +35,7 @@ $resout = extract_block($out, 'results'); if (isSet($_GET['query'])) { - $query = $_GET['query']; + $query = strip_tags($_GET['query']); $output = empty($_GET['output']) ? '' : $_GET['output'];