summaryrefslogtreecommitdiff
path: root/src/game
diff options
context:
space:
mode:
Diffstat (limited to 'src/game')
-rw-r--r--src/game/g_cmds.c8
1 files changed, 8 insertions, 0 deletions
diff --git a/src/game/g_cmds.c b/src/game/g_cmds.c
index ee215301..9a225c24 100644
--- a/src/game/g_cmds.c
+++ b/src/game/g_cmds.c
@@ -1192,6 +1192,14 @@ void Cmd_CallVote_f( gentity_t *ent )
return;
}
+ // protect against the dreaded exploit of '\n'-interpretation inside quotes
+ if( strchr( arg, '\n' ) || strchr( arg, '\r' ) ||
+ strchr( creason, '\n' ) || strchr( creason, '\r' ) )
+ {
+ trap_SendServerCommand( ent-g_entities, "print \"Invalid vote string\n\"" );
+ return;
+ }
+
if( level.voteExecuteTime[ team ] )
G_ExecuteVote( team );