Fix against SMTP injection

This commit is contained in:
Laurent Destailleur 2022-11-28 16:57:06 +01:00
parent ba4e5ef245
commit db6ee9f75f

View File

@ -329,10 +329,10 @@ class CMailFile
$this->addr_bcc = dol_sanitizeEmail($addr_bcc);
$this->deliveryreceipt = $deliveryreceipt;
if (empty($replyto)) {
$replyto = $from;
$replyto = dol_sanitizeEmail($from);
}
$this->reply_to = $replyto;
$this->errors_to = $errors_to;
$this->reply_to = dol_sanitizeEmail($replyto);
$this->errors_to = dol_sanitizeEmail($errors_to);
$this->trackid = $trackid;
// Set arrays with attached files info
$this->filename_list = $filename_list;