[KVE-20206-1176]XSS 취약점 - 결제 전 주문 임시데이터 저장 요청 출처 검증 추가
- shop/ajax.orderdatasave.php에 check_request_origin() 적용하여 외부 사이트발 자동 요청에 의한 임시 주문 데이터 교체 차단 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
1a5661a995
commit
d419f430a9
@@ -1,6 +1,9 @@
|
||||
<?php
|
||||
include_once('./_common.php');
|
||||
|
||||
// 요청 출처 검증
|
||||
if (function_exists('check_request_origin')) check_request_origin(G5_SHOP_URL);
|
||||
|
||||
if(empty($_POST))
|
||||
die('정보가 넘어오지 않았습니다.');
|
||||
|
||||
|
||||
Reference in New Issue
Block a user