[KVE-2026-1233]취약점- 게시글 조회 시 wr_id 정수 처리 보완

- get_write() 진입 시 wr_id를 정수로 캐스팅하여 SQL 조건에 비정상 값이 전달되지 않도록 보완

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
thisgun
2026-06-30 02:05:11 +00:00
co-authored by Claude Opus 4.8
parent e0a42d8f46
commit d7d5f26524
+2
View File
@@ -924,6 +924,8 @@ function get_write($write_table, $wr_id, $is_cache=false)
{
global $g5, $g5_object;
$wr_id = (int) $wr_id;
$wr_bo_table = preg_replace('/^'.preg_quote($g5['write_prefix']).'/i', '', $write_table);
$write = $g5_object->get('bbs', $wr_id, $wr_bo_table);