diff --git a/classes/local/outagelib.php b/classes/local/outagelib.php index 35565d3..76db68e 100644 --- a/classes/local/outagelib.php +++ b/classes/local/outagelib.php @@ -267,6 +267,10 @@ class outagelib { // single-quotes (and double for the sake of it) are present otherwise it would break the code. $allowedips = addslashes($allowedips); + // Escape the access key before substitution into the PHP literal to prevent + // code injection via a maliciously crafted access key value. + $accesskey = addslashes((string)$accesskey); + $cookiesecure = is_moodle_cookie_secure(); // Since Moodle 4.3 cookiehttponly is default to true and this CFG is not set. diff --git a/version.php b/version.php index 3e06da0..cfb30fb 100644 --- a/version.php +++ b/version.php @@ -28,8 +28,8 @@ defined('MOODLE_INTERNAL') || die(); $plugin->component = "auth_outage"; -$plugin->version = 2026011304; // The current plugin version (Date: YYYYMMDDXX). -$plugin->release = 2026011304; // Human-readable release information. +$plugin->version = 2026011305; // The current plugin version (Date: YYYYMMDDXX). +$plugin->release = 2026011305; // Human-readable release information. $plugin->requires = 2025100600; // Moodle 5.1. $plugin->maturity = MATURITY_STABLE; // Suitable for PRODUCTION environments! $plugin->supported = [501, 501]; // A range of branch numbers of supported moodle versions.