diff --git a/app/Controller/AvatarFileController.php b/app/Controller/AvatarFileController.php index 327080d28..ed8a10288 100644 --- a/app/Controller/AvatarFileController.php +++ b/app/Controller/AvatarFileController.php @@ -30,6 +30,7 @@ class AvatarFileController extends BaseController */ public function upload() { + $this->checkCSRFParam(); $user = $this->getUser(); if (! $this->avatarFileModel->uploadImageFile($user['id'], $this->request->getFileInfo('avatar'))) { diff --git a/app/Template/avatar_file/show.php b/app/Template/avatar_file/show.php index 1766cb3f9..f10fac06c 100644 --- a/app/Template/avatar_file/show.php +++ b/app/Template/avatar_file/show.php @@ -13,8 +13,7 @@