Bug 32457: Fix CGI vulnerability in addorder.pl
authorMarcel de Rooy <m.de.rooy@rijksmuseum.nl>
Tue, 13 Dec 2022 14:31:10 +0000 (14:31 +0000)
committerTomas Cohen Arazi <tomascohen@theke.io>
Wed, 14 Dec 2022 18:07:09 +0000 (15:07 -0300)
Test plan:
Go to acqui/addorder.pl.
Create two items.
Check if results still match your expectations.

Signed-off-by: Marcel de Rooy <m.de.rooy@rijksmuseum.nl>
Signed-off-by: Tomas Cohen Arazi <tomascohen@theke.io>
acqui/addorder.pl

index 147d168..25fd4b3 100755 (executable)
@@ -190,7 +190,7 @@ unless($confirm_budget_exceeding) {
         foreach (keys %$vars) {
             push @vars_loop, {
                 name => $_,
-                values => [$input->param($_)],
+                values => [ $input->multi_param($_) ],
             };
         }