Plugin Directory

Changeset 3264854


Ignore:
Timestamp:
04/01/2025 06:00:52 AM (12 months ago)
Author:
rohitashv
Message:

xss vurnablity removed

Location:
emarksheet
Files:
41 added
8 edited

Legend:

Unmodified
Added
Removed
  • emarksheet/tags/5.2/emarksheet.php

    r3263284 r3264854  
    55Description: This is a simple and unique wordpress plugin to create a simple marksheet using wordpress. You can also give a link to your users to see the result and print it.
    66Author: rohitashv
    7 Version: 5.2
     7Version: 5.4.0
    88License:           GPL v2 or later
    99License URI:       https://www.gnu.org/licenses/gpl-2.0.html
  • emarksheet/tags/5.2/readme.txt

    r3263284 r3264854  
    55Requires at least: 4.1
    66Tested up to: 6.7.2
    7 Stable tag: 5.2
     7Stable tag: 5.4.0
    88
    99This is a simple and unique wordpress plugin to create a simple marksheet using wordpress. You can also give a link to your users to see the result and print it.
     
    109109=5.0=
    110110Minor Bug Resolved
     111
     112=5.4.0=
     113XSS Vulnerability found
  • emarksheet/trunk/emarksheet.php

    r3263284 r3264854  
    55Description: This is a simple and unique wordpress plugin to create a simple marksheet using wordpress. You can also give a link to your users to see the result and print it.
    66Author: rohitashv
    7 Version: 5.2
     7Version: 5.4.0
    88License:           GPL v2 or later
    99License URI:       https://www.gnu.org/licenses/gpl-2.0.html
  • emarksheet/trunk/menu-pages/emark_add_class.php

    r1630687 r3264854  
    2222if($_GET['action']=='delete')
    2323{
    24     $iddelt = $_GET['id'];
     24    $iddelt = esc_html($_GET['id']);
    2525    $delete_query = "delete from `emarksheet_class` where `id`='$iddelt'";
    2626    $wpdb->query($delete_query);
     
    4545if($_GET['action']=='update')
    4646{
    47     $idd = $_GET['id'];
     47    $idd = esc_html($_GET['id']);
    4848    $selectd_query = "select * from `emarksheet_class` where `id`='$idd'";
    4949    $selectd_row =  $wpdb->get_results($selectd_query);
  • emarksheet/trunk/menu-pages/emark_add_marks.php

    r3263284 r3264854  
    77if(isset($_GET['action']))
    88{
    9     $id = $_GET['id'];
     9    $id = esc_html($_GET['id']);
    1010    $selectd_query = "select * from `emarksheet_student` where `id`='$id'";
    1111    $selectd_row =  $wpdb->get_results($selectd_query);
     
    3434{
    3535    if(isset($_POST['get_st_lt'])) 
    36         $class_n = $_POST['class_n'];
     36        $class_n = esc_html($_POST['class_n']);
    3737    else{
    38         $class_n = $_GET['class_id'];
    39         $student_id = $_POST['st_id'];
     38        $class_n = esc_html($_GET['class_id']);
     39        $student_id = esc_html($_POST['st_id']);
    4040        $data = serialize($_POST);
    4141        $gt_old = "select * from `emarksheet_marks` where `student_id`='$student_id' AND `class_id`='$class_n'";
     
    109109}
    110110?>
    111 
  • emarksheet/trunk/menu-pages/emark_add_student_list.php

    r1170706 r3264854  
    1212if(isset($_POST['update_name']))
    1313{
    14     $up_id = $_POST['up_id'];
    15     $class = $_POST['class_nm'];
    16     $roll_n = $_POST['roll_number'];
    17     $first_n = $_POST['first_n'];
    18     $last_n = $_POST['last_n'];
    19     $father_n = $_POST['f_name'];
    20     $mother_n = $_POST['m_name'];
    21     $dob_date = $_POST['dob_date'];
    22     $dob_m= $_POST['dob_month'];
    23     $dob_y = $_POST['dob_year'];
     14    $up_id = esc_html($_POST['up_id']);
     15    $class = esc_html($_POST['class_nm']);
     16    $roll_n = esc_html($_POST['roll_number']);
     17    $first_n = esc_html($_POST['first_n']);
     18    $last_n = esc_html($_POST['last_n']);
     19    $father_n = esc_html($_POST['f_name']);
     20    $mother_n = esc_html($_POST['m_name']);
     21    $dob_date = esc_html($_POST['dob_date']);
     22    $dob_m= esc_html($_POST['dob_month']);
     23    $dob_y = esc_html($_POST['dob_year']);
    2424    $update_query = "update `emarksheet_student` set `class_id`='$class',
    2525    `roll_no`='$roll_n',`first_n`='$first_n',`last_n`='$last_n',`father_n`='$father_n',`mother_n`='$mother_n',
  • emarksheet/trunk/menu-pages/emark_add_sub.php

    r1630687 r3264854  
    3737if($_GET['action']=='delete')
    3838{
    39     $iddelt = $_GET['id'];
     39    $iddelt = esc_html($_GET['id']);
    4040    $delete_query = "delete from `emarksheet_subject` where `id`='$iddelt'";
    4141    $wpdb->query($delete_query);
  • emarksheet/trunk/readme.txt

    r3263284 r3264854  
    55Requires at least: 4.1
    66Tested up to: 6.7.2
    7 Stable tag: 5.2
     7Stable tag: 5.4.0
    88
    99This is a simple and unique wordpress plugin to create a simple marksheet using wordpress. You can also give a link to your users to see the result and print it.
     
    109109=5.0=
    110110Minor Bug Resolved
     111
     112=5.4.0=
     113XSS Vulnerability resolved
Note: See TracChangeset for help on using the changeset viewer.