@@ -451,7 +451,7 @@ function monitorRenderPrimaryFilterRow(array $dashboards, array $monitor_status,
451451 }
452452
453453 print '<input type="button" value=" ' . (get_request_var ('mute ' ) == 'false ' ? getMuteText () : getUnmuteText ()) . '" id="sound" title=" ' . (get_request_var ('mute ' ) == 'false ' ? __ ('%s Alert for downed Devices ' , getMuteText (), 'monitor ' ) : __ ('%s Alerts for downed Devices ' , getUnmuteText (), 'monitor ' )) . '"> ' . PHP_EOL ;
454- print '<input id="downhosts" type="hidden" value=" ' . get_request_var ('downhosts ' ) . '"><input id="mute" type="hidden" value=" ' . get_request_var ('mute ' ) . '"> ' . PHP_EOL ;
454+ print '<input id="downhosts" type="hidden" value=" ' . html_escape ( get_request_var ('downhosts ' )) . '"><input id="mute" type="hidden" value=" ' . html_escape ( get_request_var ('mute ' ) ) . '"> ' . PHP_EOL ;
455455 print '</span></td> ' ;
456456}
457457
@@ -549,23 +549,23 @@ function monitorRenderGroupingDropdowns(array $classes, array $criticalities, ar
549549 */
550550function monitorRenderHiddenFilterInputs (): void {
551551 if (get_request_var ('grouping ' ) != 'tree ' ) {
552- print '<td><input type="hidden" id="tree" value=" ' . get_request_var ('tree ' ) . '"></td> ' . PHP_EOL ;
552+ print '<td><input type="hidden" id="tree" value=" ' . html_escape ( get_request_var ('tree ' ) ) . '"></td> ' . PHP_EOL ;
553553 }
554554
555555 if (get_request_var ('grouping ' ) != 'site ' ) {
556- print '<td><input type="hidden" id="site" value=" ' . get_request_var ('site ' ) . '"></td> ' . PHP_EOL ;
556+ print '<td><input type="hidden" id="site" value=" ' . html_escape ( get_request_var ('site ' ) ) . '"></td> ' . PHP_EOL ;
557557 }
558558
559559 if (get_request_var ('grouping ' ) != 'template ' ) {
560- print '<td><input type="hidden" id="template" value=" ' . get_request_var ('template ' ) . '"></td> ' . PHP_EOL ;
560+ print '<td><input type="hidden" id="template" value=" ' . html_escape ( get_request_var ('template ' ) ) . '"></td> ' . PHP_EOL ;
561561 }
562562
563563 if (get_request_var ('view ' ) == 'list ' ) {
564- print '<td><input type="hidden" id="size" value=" ' . get_request_var ('size ' ) . '"></td> ' . PHP_EOL ;
564+ print '<td><input type="hidden" id="size" value=" ' . html_escape ( get_request_var ('size ' ) ) . '"></td> ' . PHP_EOL ;
565565 }
566566
567567 if (get_request_var ('view ' ) != 'default ' ) {
568- print '<td><input type="hidden" id="trim" value=" ' . get_request_var ('trim ' ) . '"></td> ' . PHP_EOL ;
568+ print '<td><input type="hidden" id="trim" value=" ' . html_escape ( get_request_var ('trim ' ) ) . '"></td> ' . PHP_EOL ;
569569 }
570570}
571571
0 commit comments