From d6b4fed0a1a1fee8589ac5c5e91cee4b5f8f4c4a Mon Sep 17 00:00:00 2001 From: stronk7 Date: Thu, 25 Sep 2008 22:42:58 +0000 Subject: [PATCH] Protect message settings with sesskey. MDL-16688 ; merged from 19_STABLE --- message/lib.php | 2 +- message/settings.html | 5 ++++- 2 files changed, 5 insertions(+), 2 deletions(-) diff --git a/message/lib.php b/message/lib.php index 9a26a84c36..4e97406cce 100644 --- a/message/lib.php +++ b/message/lib.php @@ -205,7 +205,7 @@ function message_print_search() { function message_print_settings() { global $USER; - if ($frm = data_submitted()) { + if ($frm = data_submitted() and confirm_sesskey()) { $pref = array(); $pref['message_showmessagewindow'] = (isset($frm->showmessagewindow)) ? '1' : '0'; diff --git a/message/settings.html b/message/settings.html index 78974203ff..3b21846154 100644 --- a/message/settings.html +++ b/message/settings.html @@ -1,5 +1,8 @@
-
+
+ + +
-- 2.39.5