php-gettext / Gettext

PHP library to collect and manipulate gettext (.po, .mo, .php, .json, etc)
MIT License
690 stars 135 forks source link

php injection - validate eval input from plural forms #156

Closed soukicz closed 7 years ago

soukicz commented 7 years ago

There wasn't any input validation on eval'd code in plural forms. Untrusted translation files could create php injection.

oscarotero commented 7 years ago

Thank you 👍