From 357316cdf956b83df890b7bc14b772f49159c3df Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Fr=C3=A9d=C3=A9ric=20Guillot?=
Date: Mon, 29 Jan 2018 11:31:54 -0800
Subject: [PATCH] Add missing CSRF check in saveUploadDB() method
---
app/Controller/ConfigController.php | 1 +
app/Template/config/upload_db.php | 4 +---
2 files changed, 2 insertions(+), 3 deletions(-)
diff --git a/app/Controller/ConfigController.php b/app/Controller/ConfigController.php
index 2ea04b35e..fcdd6972b 100644
--- a/app/Controller/ConfigController.php
+++ b/app/Controller/ConfigController.php
@@ -199,6 +199,7 @@ class ConfigController extends BaseController
*/
public function saveUploadedDb()
{
+ $this->checkCSRFParam();
$filename = $this->request->getFilePath('file');
if (!file_exists($filename) || !$this->configModel->uploadDatabase($filename)) {
diff --git a/app/Template/config/upload_db.php b/app/Template/config/upload_db.php
index b247cf751..efc8eb28b 100644
--- a/app/Template/config/upload_db.php
+++ b/app/Template/config/upload_db.php
@@ -8,9 +8,7 @@
-