From 54211267437a7f9f6b648f811b87b8b1f030e32c Mon Sep 17 00:00:00 2001 From: nikrou Date: Mon, 13 Sep 2010 19:40:42 +0000 Subject: Fix bug 1856 : CSRF issue that allow to change admin password git-svn-id: http://piwigo.org/svn/trunk@6897 68402e56-0260-453c-a942-63ccdbb3a9ee --- admin/profile.php | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) (limited to 'admin/profile.php') diff --git a/admin/profile.php b/admin/profile.php index f1d5e08e3..ebb372518 100644 --- a/admin/profile.php +++ b/admin/profile.php @@ -25,8 +25,12 @@ if( !defined("PHPWG_ROOT_PATH") ) die ("Hacking attempt!"); $edit_user = build_user( $_GET['user_id'], false ); -include_once(PHPWG_ROOT_PATH.'profile.php'); +if (!empty($_POST)) +{ + check_pwg_token(); +} +include_once(PHPWG_ROOT_PATH.'profile.php'); $errors = array(); if ( !is_adviser() ) -- cgit v1.2.3