kakwa / ldapcherry

Web UI for managing users and groups in multiple directory services.
MIT License
225 stars 70 forks source link

Improperly escaped parameters in querystring #19

Closed kakwa closed 5 years ago

kakwa commented 5 years ago

Various links generated through the application look like that: https://ldapcherry.kakwalab.ovh/modify?user=

but is not properly escaped/encoded to be introduced in the querystring, this needs to be fixed.