[KVE-2026-1233]취약점- 게시글 조회 시 wr_id 정수 처리 보완
- get_write() 진입 시 wr_id를 정수로 캐스팅하여 SQL 조건에 비정상 값이 전달되지 않도록 보완 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
e0a42d8f46
commit
d7d5f26524
@@ -924,6 +924,8 @@ function get_write($write_table, $wr_id, $is_cache=false)
|
||||
{
|
||||
global $g5, $g5_object;
|
||||
|
||||
$wr_id = (int) $wr_id;
|
||||
|
||||
$wr_bo_table = preg_replace('/^'.preg_quote($g5['write_prefix']).'/i', '', $write_table);
|
||||
|
||||
$write = $g5_object->get('bbs', $wr_id, $wr_bo_table);
|
||||
|
||||
Reference in New Issue
Block a user