DedeCMS v5.7 qrcode二维码XSS跨1449;脚本制作漏洞补丁:
开启 /Plus/qrcode.PHP 寻找,大约在第八行
<span style="font-size:14px;">$type = isset($type)? $type : '';</span> |
改动为:
<span style="font-size:14px;">$type = isset($type)? RemoveXSS(htmLReplace($type,3)) : '';</span> |