1
0
Fork 0

Merge pull request #9166 from MrPetovan/bug/phpinfo-accessible-hotfix

[Hotfix] Fix security vulnerability in admin modules
This commit is contained in:
Tobias Diekershoff 2020-09-08 19:56:26 +02:00 committed by GitHub
commit fb721f8e30
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
20 changed files with 497 additions and 574 deletions

View file

@ -24,6 +24,7 @@
{{if $admin_form}}
<h3>{{$settings}}</h3>
<form method="post" action="{{$baseurl}}/admin/{{$function}}/{{$addon}}">
<input type="hidden" name="form_security_token" value="{{$form_security_token}}">
{{$admin_form nofilter}}
</form>
{{/if}}

View file

@ -10,7 +10,7 @@
<ul>
<li><a href="{{$baseurl}}/admin/dbsync/mark/{{$f}}">{{$mark}}</a></li>
<li><a href="{{$baseurl}}/admin/dbsync/{{$f}}">{{$apply}}</a></li>
<li><a href="{{$baseurl}}/admin/dbsync/update/{{$f}}">{{$apply}}</a></li>
</ul>
<hr />