diff --git a/system/pages/highscores.php b/system/pages/highscores.php index 53f2c8e4..de1a36be 100644 --- a/system/pages/highscores.php +++ b/system/pages/highscores.php @@ -18,6 +18,10 @@ $list = isset($_GET['list']) ? $_GET['list'] : ''; $_page = isset($_GET['page']) ? $_GET['page'] : 0; $vocation = isset($_GET['vocation']) ? $_GET['vocation'] : NULL; +if(!is_numeric($_page) || $_page < 1 || $_page > PHP_INT_MAX) { + $_page = 1; +} + $add_sql = ''; $config_vocations = $config['vocations']; if($config['highscores_vocation_box'] && isset($vocation))