From f9060f8300336b1fc792602a56308e883c27f3aa Mon Sep 17 00:00:00 2001 From: Ivan Kohler Date: Mon, 12 Nov 2012 00:02:42 -0800 Subject: [PATCH] fix XSS --- FS/FS/ClientAPI/MyAccount.pm | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/FS/FS/ClientAPI/MyAccount.pm b/FS/FS/ClientAPI/MyAccount.pm index d07b3834e..3364b97df 100644 --- a/FS/FS/ClientAPI/MyAccount.pm +++ b/FS/FS/ClientAPI/MyAccount.pm @@ -2037,8 +2037,8 @@ sub _usage_details { $p->{ending} = $end; } - die "illegal beginning" if $beginning !~ /^\d*$/; - die "illegal ending" if $ending !~ /^\d*$/; + die "illegal beginning" if $p->{beginning} !~ /^\d*$/; + die "illegal ending" if $p->{ending} !~ /^\d*$/; my (@usage) = &$callback($svc_x, $p->{beginning}, $p->{ending}, %callback_opt -- 2.11.0