diff --git a/classes/local/outagelib.php b/classes/local/outagelib.php index 77f8280..15c40c9 100644 --- a/classes/local/outagelib.php +++ b/classes/local/outagelib.php @@ -267,6 +267,10 @@ class outagelib { // single-quotes (and double for the sake of it) are present otherwise it would break the code. $allowedips = addslashes($allowedips); + // Escape the access key before substitution into the PHP literal to prevent + // code injection via a maliciously crafted access key value. + $accesskey = addslashes((string)$accesskey); + $cookiesecure = is_moodle_cookie_secure(); // Since Moodle 4.3 cookiehttponly is default to true and this CFG is not set. diff --git a/version.php b/version.php index ac32760..df16521 100644 --- a/version.php +++ b/version.php @@ -28,8 +28,8 @@ defined('MOODLE_INTERNAL') || die(); $plugin->component = "auth_outage"; -$plugin->version = 2024081905; // The current plugin version (Date: YYYYMMDDXX). -$plugin->release = 2024081905; // Human-readable release information. +$plugin->version = 2024081906; // The current plugin version (Date: YYYYMMDDXX). +$plugin->release = 2024081906; // Human-readable release information. $plugin->requires = 2017111309; // 2017111309 = T13, but this really requires 3.9 and higher. $plugin->maturity = MATURITY_STABLE; // Suitable for PRODUCTION environments! $plugin->supported = [39, 405]; // A range of branch numbers of supported moodle versions.