From 45e553a4015c3b8178fb21df58fbfba6663c6d44 Mon Sep 17 00:00:00 2001 From: =?utf8?q?Tim=20D=C3=BCsterhus?= Date: Tue, 17 Nov 2020 11:14:15 +0100 Subject: [PATCH] Force the setupId to be an int in MFAuthenticationForm --- .../files/lib/form/MultifactorAuthenticationForm.class.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/wcfsetup/install/files/lib/form/MultifactorAuthenticationForm.class.php b/wcfsetup/install/files/lib/form/MultifactorAuthenticationForm.class.php index de400ac9bf..d9483ffb72 100644 --- a/wcfsetup/install/files/lib/form/MultifactorAuthenticationForm.class.php +++ b/wcfsetup/install/files/lib/form/MultifactorAuthenticationForm.class.php @@ -75,7 +75,7 @@ class MultifactorAuthenticationForm extends AbstractFormBuilderForm { $setupId = \array_keys($this->setups)[0]; if (isset($_GET['id'])) { - $setupId = $_GET['id']; + $setupId = intval($_GET['id']); } if (!isset($this->setups[$setupId])) { -- 2.20.1