Merge pull request #825 from wrongecho/csrf-stripe

Require CSRF token to edit Stripe settings - thanks to @stehled
This commit is contained in:
wrongecho 2023-11-25 16:39:14 +00:00 committed by GitHub
commit 51ac53dc50
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
2 changed files with 4 additions and 2 deletions

View File

@ -331,6 +331,7 @@ if (isset($_GET['generate_cron_key'])) {
if (isset($_POST['edit_online_payment_settings'])) { if (isset($_POST['edit_online_payment_settings'])) {
validateCSRFToken($_POST['csrf_token']);
validateAdminRole(); validateAdminRole();
$config_stripe_enable = intval($_POST['config_stripe_enable']); $config_stripe_enable = intval($_POST['config_stripe_enable']);

View File

@ -11,6 +11,7 @@ require_once "inc_all_settings.php";
</div> </div>
<div class="card-body"> <div class="card-body">
<form action="post.php" method="post" autocomplete="off"> <form action="post.php" method="post" autocomplete="off">
<input type="hidden" name="csrf_token" value="<?php echo $_SESSION['csrf_token'] ?>">
<div class="form-group"> <div class="form-group">
<div class="custom-control custom-switch"> <div class="custom-control custom-switch">