Ticket #1110: users.php.diff

File users.php.diff, 952 bytes (added by gzfelix, 7 years ago)
  • users.php

     
    2424case 'adduser': 
    2525        check_admin_referer(); 
    2626 
    27         $user_login     = wp_specialchars($_POST['user_login']); 
     27        $user_login     = wp_specialchars(trim($_POST['user_login'])); 
    2828        $pass1          = $_POST['pass1']; 
    2929        $pass2          = $_POST['pass2']; 
    30         $user_email     = wp_specialchars($_POST['email']); 
    31         $user_firstname = wp_specialchars($_POST['firstname']); 
    32         $user_lastname  = wp_specialchars($_POST['lastname']); 
    33         $user_uri       = wp_specialchars($_POST['uri']); 
     30        $user_email     = wp_specialchars(trim($_POST['email'])); 
     31        $user_firstname = wp_specialchars(trim($_POST['firstname'])); 
     32        $user_lastname  = wp_specialchars(trim($_POST['lastname'])); 
     33        $user_uri       = wp_specialchars(trim($_POST['uri'])); 
    3434                 
    3535        /* checking that username has been typed */ 
    3636        if ($user_login == '')