security fix: prevent command injection via callvote
This commit is contained in:
1 parent
cde5fcfb9b
commit
f5aae78481
4 files changed
+29
-3
No files matched your search
@@ -1500,6 +1500,7 @@ void SV_ExecuteClientCommand( client_t *cl, const char *s, qboolean clientOK ) {
|
||||
if (clientOK) {
|
||||
// pass unknown strings to the game
|
||||
if (!u->name && sv.state == SS_GAME) {
|
||||
Cmd_Args_Sanitize();
|
||||
VM_Call( gvm, GAME_CLIENT_COMMAND, cl - svs.clients );
|
||||
}
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user