[KVE-2026-1813] 미완료주문 확정 처리 필드 정제 및 결제수단 출력 인코딩

미완료주문을 주문으로 확정할 때 임시 데이터에서 복원한 결제수단, 접속 IP,
테스트 결제 여부를 정제 없이 사용하던 것을 이웃 필드와 동일한 방식으로
처리한다. 접속 IP는 표기 형식에 맞지 않으면 저장하지 않고, 테스트 결제
여부는 정수로만 저장하며, 세 값 모두 배열로 전달된 경우를 함께 걸러낸다.

임시주문 저장 시 접속 IP와 테스트 결제 여부를 서버에서 결정하는 처리가
일반 주문 분기 안에만 있어 개인결제 경로에서는 요청값이 그대로 저장되던
것을 분기 밖으로 옮겨 항상 서버 값을 사용하도록 한다.

결제수단 값이 그대로 출력되던 관리자 주문상세, 주문목록, 부분취소 화면과
구매자 주문조회 화면(웹/모바일/테마)에 get_text() 인코딩을 적용한다.
주문상세는 표시 문자열을 여러 곳에서 재사용하므로 생성 지점에서 처리한다.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 77069575096881a31b29fdf130c83226610bf8df)
This commit is contained in:
thisgun
2026-08-24 07:56:32 +00:00
parent 04a4de4923
commit ebd18b6001
9 changed files with 25 additions and 20 deletions
+6 -3
View File
@@ -246,6 +246,9 @@ $od_bank_account = isset($data['od_bank_account']) ? addslashes(clean_xss_tags(
$od_tno = '';
$od_app_no = '';
$od_hope_date = isset($data['od_hope_date']) ? addslashes(clean_xss_tags(stripslashes($data['od_hope_date']), 1, 1)) : '';
$od_ip = (isset($data['od_ip']) && !is_array($data['od_ip']) && preg_match('/^[0-9a-fA-F:.]{1,45}$/', $data['od_ip'])) ? $data['od_ip'] : '';
$od_settle_case = (isset($data['od_settle_case']) && !is_array($data['od_settle_case'])) ? addslashes(clean_xss_tags(stripslashes($data['od_settle_case']), 1, 1)) : '';
$od_test = (isset($data['od_test']) && !is_array($data['od_test'])) ? (int) $data['od_test'] : 0;
// 주문서에 입력
$sql = " insert {$g5['g5_shop_order_table']}
@@ -297,9 +300,9 @@ $sql = " insert {$g5['g5_shop_order_table']}
od_shop_memo = '',
od_hope_date = '{$od_hope_date}',
od_time = '{$od['dt_time']}',
od_ip = '{$data['od_ip']}',
od_settle_case = '{$data['od_settle_case']}',
od_test = '{$data['od_test']}'
od_ip = '$od_ip',
od_settle_case = '$od_settle_case',
od_test = '$od_test'
";
$result = sql_query($sql, true);
+7 -7
View File
@@ -497,7 +497,7 @@ if ($is_nicepay_vbank_pg_cancel) {
//$amount['미수'] = $amount['order'] - $amount['receipt'] - $amount['coupon'];
// 결제방법
$s_receipt_way = check_pay_name_replace($od['od_settle_case'], $od);
$s_receipt_way = get_text(check_pay_name_replace($od['od_settle_case'], $od));
if ($od['od_receipt_point'] > 0)
$s_receipt_way .= "+포인트";
@@ -574,7 +574,7 @@ if ($is_nicepay_vbank_pg_cancel) {
</tr>
<?php } ?>
<tr>
<th scope="row"><?php echo $od['od_settle_case']; ?> 입금액</th>
<th scope="row"><?php echo get_text($od['od_settle_case']); ?> 입금액</th>
<td><?php echo display_price($od['od_receipt_price']); ?></td>
</tr>
<tr>
@@ -597,7 +597,7 @@ if ($is_nicepay_vbank_pg_cancel) {
<td><?php echo get_text($od['od_bank_account']); ?></td>
</tr>
<tr>
<th scope="row"><?php echo $od['od_settle_case']; ?> 결제액</th>
<th scope="row"><?php echo get_text($od['od_settle_case']); ?> 결제액</th>
<td><?php echo display_price($od['od_receipt_price']); ?></td>
</tr>
<tr>
@@ -870,7 +870,7 @@ if ($is_nicepay_vbank_pg_cancel) {
<?php } ?>
<tr>
<th scope="row"><label for="od_receipt_price"><?php echo $od['od_settle_case']; ?> 입금액</label></th>
<th scope="row"><label for="od_receipt_price"><?php echo get_text($od['od_settle_case']); ?> 입금액</label></th>
<td>
<?php echo $html_receipt_chk; ?>
<input type="text" name="od_receipt_price" value="<?php echo $od['od_receipt_price']; ?>" id="od_receipt_price" class="frm_input"> 원
@@ -904,7 +904,7 @@ if ($is_nicepay_vbank_pg_cancel) {
<td><?php echo get_text($od['od_bank_account']); ?></td>
</tr>
<tr>
<th scope="row"><label for="od_receipt_price"><?php echo $od['od_settle_case']; ?> 결제액</label></th>
<th scope="row"><label for="od_receipt_price"><?php echo get_text($od['od_settle_case']); ?> 결제액</label></th>
<td>
<?php echo $html_receipt_chk; ?>
<input type="text" name="od_receipt_price" value="<?php echo $od['od_receipt_price']; ?>" id="od_receipt_price" class="frm_input"> 원
@@ -1036,7 +1036,7 @@ if ($is_nicepay_vbank_pg_cancel) {
<a href="./personalpayform.php?popup=yes&amp;od_id=<?php echo $od_id; ?>" id="personalpay_add" class="btn btn_02">개인결제추가</a>
<?php } ?>
<?php if($od['od_misu'] < 0 && ($od['od_receipt_price'] - $od['od_refund_price']) > 0 && ($od['od_settle_case'] == '신용카드' || $od['od_settle_case'] == '계좌이체' || $od['od_settle_case'] == 'KAKAOPAY' || ($od['od_pg'] == 'nicepay' && $od['od_settle_case'] == '간편결제'))) { ?>
<a href="./orderpartcancel.php?od_id=<?php echo $od_id; ?>" id="orderpartcancel" class="btn btn_02"><?php echo $od['od_settle_case']; ?> 부분취소</a>
<a href="./orderpartcancel.php?od_id=<?php echo $od_id; ?>" id="orderpartcancel" class="btn btn_02"><?php echo get_text($od['od_settle_case']); ?> 부분취소</a>
<?php } ?>
<a href="./orderlist.php?<?php echo $qstr; ?>" class="btn btn_02">목록</a>
</div>
@@ -1480,7 +1480,7 @@ function form_submit(f)
<?php if($od['od_pg'] == 'KAKAOPAY') { ?>
var cancel_pg = "카카오페이";
<?php } else { ?>
var cancel_pg = "PG사의 <?php echo $od['od_settle_case']; ?>";
var cancel_pg = "PG사의 <?php echo get_text($od['od_settle_case']); ?>";
<?php } ?>
// 체크하지 않은 나머지 품목이 모두 취소류 상태이면 이번 처리로 주문 전체가 취소된다.
+2 -2
View File
@@ -305,7 +305,7 @@ if( function_exists('pg_setting_check') ){
$s_receipt_way = $s_br = "";
if ($row['od_settle_case'])
{
$s_receipt_way = check_pay_name_replace($row['od_settle_case'], $row);
$s_receipt_way = get_text(check_pay_name_replace($row['od_settle_case'], $row));
$s_br = '<br />';
}
else
@@ -402,7 +402,7 @@ if( function_exists('pg_setting_check') ){
<?php echo $row['od_status']; ?>
</td>
<td headers="odrpay" class="odrpay">
<input type="hidden" name="current_settle_case[<?php echo $i ?>]" value="<?php echo $row['od_settle_case'] ?>">
<input type="hidden" name="current_settle_case[<?php echo $i ?>]" value="<?php echo get_text($row['od_settle_case']) ?>">
<?php echo $s_receipt_way; ?>
</td>
<td headers="delino" class="delino">
+2 -2
View File
@@ -21,7 +21,7 @@ if($od['od_settle_case'] == '계좌이체' && substr($od['od_receipt_time'], 0,
if($od['od_receipt_price'] - $od['od_refund_price'] <= 0)
alert_close('부분취소 처리할 금액이 없습니다.');
$g5['title'] = $od['od_settle_case'].' 부분취소';
$g5['title'] = get_text($od['od_settle_case']).' 부분취소';
include_once(G5_PATH.'/head.sub.php');
// 취소가능금액
@@ -33,7 +33,7 @@ $od_misu = abs($od['od_misu']);
<input type="hidden" name="od_id" value="<?php echo $od_id; ?>">
<div class="new_win">
<h1><?php echo $od['od_settle_case']; ?> 부분취소</h1>
<h1><?php echo get_text($od['od_settle_case']); ?> 부분취소</h1>
<div class="tbl_frm01 tbl_wrap">
<table>
+1 -1
View File
@@ -46,7 +46,7 @@ include_once(G5_PATH.'/head.sub.php');
?>
<script>
alert("<?php echo $od['od_settle_case']; ?> 부분취소 처리됐습니다.");
alert("<?php echo get_text($od['od_settle_case']); ?> 부분취소 처리됐습니다.");
opener.document.location.reload();
self.close();
</script>
+1 -1
View File
@@ -280,7 +280,7 @@ if($od['od_pg'] == 'lg') {
</tr>
<tr>
<th scope="row">결제방식</th>
<td><?php echo check_pay_name_replace($od['od_settle_case'], $od, 1); ?></td>
<td><?php echo get_text(check_pay_name_replace($od['od_settle_case'], $od, 1)); ?></td>
</tr>
<tr>
<th scope="row">결제금액</th>
+4 -2
View File
@@ -18,6 +18,10 @@ $od_settle_case = isset($_POST['od_settle_case']) ? clean_xss_tags($_POST['od_se
// 저장되는 원본에도 정제한 값을 반영한다.
$_POST['od_settle_case'] = $od_settle_case;
// 결제환경 정보는 요청값을 사용하지 않고 서버에서 결정한다.
$_POST['od_test'] = $default['de_card_test'];
$_POST['od_ip'] = function_exists('get_real_client_ip') ? get_real_client_ip() : $_SERVER['REMOTE_ADDR'];
if(isset($_POST['pp_id']) && $_POST['pp_id']) {
$od_id = get_session('ss_personalpay_id');
$cart_id = 0;
@@ -34,8 +38,6 @@ if(isset($_POST['pp_id']) && $_POST['pp_id']) {
} else {
$od_id = get_session('ss_order_id');
$_POST['sw_direct'] = get_session('ss_direct');
$_POST['od_test'] = $default['de_card_test'];
$_POST['od_ip'] = $_SERVER['REMOTE_ADDR'];
if ($_POST['sw_direct']) {
$cart_id = get_session('ss_cart_direct');
+1 -1
View File
@@ -278,7 +278,7 @@ if($od['od_pg'] == 'lg') {
</tr>
<tr>
<th scope="row">결제방식</th>
<td><?php echo check_pay_name_replace($od['od_settle_case'], $od, 1); ?></td>
<td><?php echo get_text(check_pay_name_replace($od['od_settle_case'], $od, 1)); ?></td>
</tr>
<tr>
<th scope="row">결제금액</th>
+1 -1
View File
@@ -403,7 +403,7 @@ if($od['od_pg'] == 'lg') {
</li>
<li>
<strong>결제방식</strong>
<span><?php echo check_pay_name_replace($od['od_settle_case'], $od, 1); ?></span>
<span><?php echo get_text(check_pay_name_replace($od['od_settle_case'], $od, 1)); ?></span>
</li>
<li>
<strong>결제금액</strong>