$jump = optional_param('jump', '', PARAM_RAW);
+ if (!confirm_sesskey()) {
+ print_error('confirmsesskeybad');
+ }
+
if (strpos($jump, $CFG->wwwroot) === 0) { // Anything on this site
redirect(urldecode($jump));
} else if (preg_match('/^[a-z]+\.php\?/', $jump)) {
}
$output .= '</select>';
+ $output .= '<input type="hidden" name="sesskey" value="'.sesskey().'" />';
$output .= '<noscript id="noscript'.$formname.'" style="display: inline;">';
$output .= '<input type="submit" value="'.$go.'" /></noscript>';
$output .= '<script type="text/javascript">'.