From 69f9d7609e932b479062b639e6df1d38c8af6df1 Mon Sep 17 00:00:00 2001 From: galenskap Date: Wed, 27 Aug 2025 09:39:23 +0200 Subject: [PATCH] Security enhancements on contact form --- src/form/contact-form-handler.php | 39 ++++++++++++++++++++----------- 1 file changed, 26 insertions(+), 13 deletions(-) diff --git a/src/form/contact-form-handler.php b/src/form/contact-form-handler.php index 5679059..c2fc0e8 100644 --- a/src/form/contact-form-handler.php +++ b/src/form/contact-form-handler.php @@ -1,4 +1,11 @@ ", $emailBody); @@ -114,7 +127,7 @@ if(empty($errors)) { //Recipients $mail->setFrom($myEmail); $mail->addAddress($wantedContact); - $mail->addReplyTo($emailAddress, $name); + $mail->addReplyTo($emailAddress, htmlspecialchars($name, ENT_QUOTES, 'UTF-8')); // Content $mail->isHTML(true); @@ -140,7 +153,7 @@ if(empty($errors)) { http_response_code(500); echo json_encode([ 'success' => false, - 'errors' => ["Erreur lors de l'envoi du message : " . $mail->ErrorInfo] + 'errors' => ["Erreur lors de l'envoi du message. Veuillez réessayer plus tard."] ]); } } else { -- 2.30.2