Hi there,
the user $_GET['user'] parameter is vulnerable to arbitrary Javascript code injection.
Please change
to
$user = htmlspecialchars($_GET['user'], ENT_QUOTES | ENT_SUBSTITUTE, 'UTF-8', true);

I haven't checked the rest of the application yet, but please consider this everywhere.
For Strings use:
$var_clean = htmlspecialchars($var, ENT_QUOTES | ENT_SUBSTITUTE, 'UTF-8', true);
For Integer use:
$var_clean = intval($var);
For Floats use:
$var_clean = floatval($var);
Hi there,
the user $_GET['user'] parameter is vulnerable to arbitrary Javascript code injection.
Please change
to
I haven't checked the rest of the application yet, but please consider this everywhere.
For Strings use:
For Integer use:
For Floats use: