Browse code

Check input types on login

Hanno Böck authored on02/05/2020 12:06:09
Showing1 changed files
... ...
@@ -44,6 +44,7 @@ if (have_module('webmailtotp') && isset($_POST['webinterface_totpcode']) && isse
44 44
 }
45 45
 
46 46
 if (isset($_POST['webinterface_username']) && isset($_POST['webinterface_password'])) {
47
+    check_input_types($_POST, array('webinterface_username' => 'string', 'webinterface_password' => 'string'));
47 48
     $role = find_role($_POST['webinterface_username'], $_POST['webinterface_password']);
48 49
     if ($role === null) {
49 50
         $_SESSION['role'] = ROLE_ANONYMOUS;