Prevents RCE via unserialize()
This commit is contained in:
@@ -1,8 +1,8 @@
|
|||||||
@extends('themes.default1.client.layout.client')
|
@extends('themes.default1.client.layout.client')
|
||||||
@section('content')
|
@section('content')
|
||||||
<?php
|
<?php
|
||||||
$tickets = App\Model\helpdesk\Ticket\Tickets::where('id', '=', \Crypt::decrypt($id))->first();
|
$tickets = App\Model\helpdesk\Ticket\Tickets::where('id', '=', \Crypt::decrypt($id, false))->first();
|
||||||
$thread = App\Model\helpdesk\Ticket\Ticket_Thread::where('ticket_id', '=', \Crypt::decrypt($id))->first();
|
$thread = App\Model\helpdesk\Ticket\Ticket_Thread::where('ticket_id', '=', \Crypt::decrypt($id, false))->first();
|
||||||
//$user = App\User::where('id','=',$id1)->first();
|
//$user = App\User::where('id','=',$id1)->first();
|
||||||
?>
|
?>
|
||||||
<!-- Main content -->
|
<!-- Main content -->
|
||||||
@@ -461,7 +461,7 @@ $thread = App\Model\helpdesk\Ticket\Ticket_Thread::where('ticket_id', '=', \Cryp
|
|||||||
</div>
|
</div>
|
||||||
@endif
|
@endif
|
||||||
|
|
||||||
<?php $id2 = Crypt::decrypt($id); ?>
|
<?php $id2 = Crypt::decrypt($id, false); ?>
|
||||||
|
|
||||||
<div id="respond" class="comment-respond form-border">
|
<div id="respond" class="comment-respond form-border">
|
||||||
|
|
||||||
|
@@ -16,8 +16,8 @@
|
|||||||
|
|
||||||
@section('content')
|
@section('content')
|
||||||
<?php
|
<?php
|
||||||
$tickets = App\Model\helpdesk\Ticket\Tickets::where('id','=',\Crypt::decrypt($id))->first();
|
$tickets = App\Model\helpdesk\Ticket\Tickets::where('id','=',\Crypt::decrypt($id, false))->first();
|
||||||
$thread = App\Model\helpdesk\Ticket\Ticket_Thread::where('ticket_id','=',\Crypt::decrypt($id))->first();
|
$thread = App\Model\helpdesk\Ticket\Ticket_Thread::where('ticket_id','=',\Crypt::decrypt($id, false))->first();
|
||||||
//$user = App\User::where('id','=',$id1)->first();?>
|
//$user = App\User::where('id','=',$id1)->first();?>
|
||||||
|
|
||||||
<!-- Main content -->
|
<!-- Main content -->
|
||||||
@@ -350,7 +350,7 @@ foreach ($conversations as $conversation) {
|
|||||||
{{Session::get('fails1')}}
|
{{Session::get('fails1')}}
|
||||||
</div>
|
</div>
|
||||||
@endif
|
@endif
|
||||||
<?php $id2 = Crypt::decrypt($id); ?>
|
<?php $id2 = Crypt::decrypt($id, false); ?>
|
||||||
<div id="respond" class="comment-respond form-border">
|
<div id="respond" class="comment-respond form-border">
|
||||||
<h3 id="reply-title" class="comment-reply-title section-title"><i class="line"></i>{!! Lang::get('lang.leave_a_reply') !!}</h3>
|
<h3 id="reply-title" class="comment-reply-title section-title"><i class="line"></i>{!! Lang::get('lang.leave_a_reply') !!}</h3>
|
||||||
@if(Auth::user())
|
@if(Auth::user())
|
||||||
|
@@ -2,8 +2,8 @@
|
|||||||
|
|
||||||
@section('content')
|
@section('content')
|
||||||
<?php
|
<?php
|
||||||
$tickets = App\Model\helpdesk\Ticket\Tickets::where('id', '=', \Crypt::decrypt($id))->first();
|
$tickets = App\Model\helpdesk\Ticket\Tickets::where('id', '=', \Crypt::decrypt($id,false))->first();
|
||||||
$thread = App\Model\helpdesk\Ticket\Ticket_Thread::where('ticket_id', '=', \Crypt::decrypt($id))->first();
|
$thread = App\Model\helpdesk\Ticket\Ticket_Thread::where('ticket_id', '=', \Crypt::decrypt($id,false))->first();
|
||||||
//$user = App\User::where('id','=',$id1)->first();
|
//$user = App\User::where('id','=',$id1)->first();
|
||||||
?>
|
?>
|
||||||
<!-- Main content -->
|
<!-- Main content -->
|
||||||
@@ -345,7 +345,7 @@ foreach ($conversations as $conversation) {
|
|||||||
{{Session::get('fails1')}}
|
{{Session::get('fails1')}}
|
||||||
</div>
|
</div>
|
||||||
@endif
|
@endif
|
||||||
<?php $id2 = Crypt::decrypt($id); ?>
|
<?php $id2 = Crypt::decrypt($id,false); ?>
|
||||||
<div id="respond" class="comment-respond form-border">
|
<div id="respond" class="comment-respond form-border">
|
||||||
<h3 id="reply-title" class="comment-reply-title section-title"><i class="line"></i>{!! Lang::get('lang.leave_a_reply') !!}</h3>
|
<h3 id="reply-title" class="comment-reply-title section-title"><i class="line"></i>{!! Lang::get('lang.leave_a_reply') !!}</h3>
|
||||||
@if(Auth::user())
|
@if(Auth::user())
|
||||||
|
Reference in New Issue
Block a user